Act nowDisclosed

Advisory · CVE-2026-103765

Mooncake HTTP metadata server has no authentication, allowing transfer redirection

Mooncake through 0.3.13.post1 exposes an unauthenticated /metadata handler that lets attackers rewrite transfer engine metadata, poison segment descriptors, and redirect KV cache transfers.

Vendor
kvcache-ai
Product
Mooncake
Identifier / CWE
CVE-2026-103765
CWE-306
Action timing
Immediate
ELI5

Explain it like I’m five

The metadata server is the phone book that tells Mooncake engines where to send cached data, and it lets anyone rewrite the listings. An attacker can repoint entries at their own machine and have cache transfers delivered to them, or scribble until the book falls apart.

SIMPLIFIED_ATTACK_PATH04 STEPS
  1. 01Unauthenticated request

    An attacker calls the HTTP metadata server's /metadata handler without any credentials.

  2. 02Metadata read and rewrite

    The handler allows reading, overwriting, and deleting transfer engine metadata keys.

  3. 03Descriptor poisoning

    The attacker poisons segment descriptors such as tcp_data_port or re-creates rpc_meta entries pointing at attacker-controlled listeners.

  4. 04Transfer hijack or exhaustion

    KV cache transfers are redirected to the attacker's listener, or repeated writes exhaust server memory and stall the service.

What happened

VulnCheck disclosed CVE-2026-103765 on October 2, 2026, rated critical at CVSS 9.4 (v3.1). The Mooncake HTTP metadata server’s /metadata handler performs no authentication, and the flaw affects Mooncake through 0.3.13.post1, the newest stable release at disclosure.

Anyone who can reach the metadata endpoint can read, overwrite, and delete the keys engines use to find each other. Poisoning a segment descriptor such as tcp_data_port, or re-creating rpc_meta entries, redirects KV cache transfers to attacker-controlled listeners; sustained writes can also exhaust server memory. Unlike CVE-2026-103764, no fixed release exists yet, so mitigation is network-level until the project ships one.

What to do

  1. Inventory Mooncake deployments and identify every host running the HTTP metadata server.
  2. Restrict the metadata port to trusted cluster networks with firewall rules or network policy; never expose it to untrusted networks or shared tenant networks.
  3. Watch metadata server logs and key churn for unexpected deletions, descriptor changes, or endpoints you do not recognize.
  4. Track the Mooncake release line and upgrade as soon as a fixed release is published; at disclosure, 0.3.13.post1 remains affected.
  5. If the metadata port was reachable from untrusted networks, review which transfers were redirected and treat redirected KV cache contents as potentially exposed.

Management note

This is the control-plane companion to CVE-2026-103764: same product family, same fix discipline. The metadata service decides where inference data flows, so it deserves the same network perimeter as the data plane until a patched release lands.