CVE-2026-104433
published 2026-10-03CVE-2026-104433: Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.37%
28.2th percentile
Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attackers can connect to the handshake port listening on all interfaces and send an eight-byte frame to terminate the hosting process, such as an SGLang inference server.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| kvcache-ai | mooncake | < 0.3.12 | 0.3.12 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending
ghsa_unreviewed·2026-10-03
CVE-2026-104433 [HIGH] CWE-125 Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending
Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attackers can connect to the handshake port listening on all interfaces and send an eight-byte frame to terminate the hosting process, such as an SGLang inference server.
VulDB
kvcache-ai Mooncake up to 0.3.11 Handshake include/common.h readString out-of-bounds
vuldb·2026-10-03·CVSS 7.5
CVE-2026-104433 [HIGH] kvcache-ai Mooncake up to 0.3.11 Handshake include/common.h readString out-of-bounds
A vulnerability marked as problematic has been reported in kvcache-ai Mooncake up to 0.3.11. Affected by this issue is the function readString of the file include/common.h of the component Handshake. The manipulation leads to out-of-bounds read.
This vulnerability is traded as CVE-2026-104433. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/kvcache-ai/Mooncakehttps://github.com/kvcache-ai/Mooncake/commit/c142b40590259360196d8e504b2193382529e7b4https://github.com/kvcache-ai/Mooncake/issues/4452https://www.vulncheck.com/advisories/mooncake-before-0.3.12-out-of-bounds-read-via-p2p-handshake-readstringhttps://github.com/kvcache-ai/Mooncake/issues/4452
2026-10-03
Published