Kvcache-Ai Mooncake vulnerabilities
13 known vulnerabilities affecting kvcache-ai/mooncake.
Total CVEs
13
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH5MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2026-106037P2CRITICALCVSS 9.8≤ 0.3.13.post12026-10-06
CVE-2026-106037 [CRITICAL] CWE-306 CVE-2026-106037: Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the Store REST serv
Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the Store REST service, which binds to 0.0.0.0 without authentication on any route. Unauthenticated attackers can call routes such as /api/get, /api/put, /api/remove_all and /api/mount to read cached KV data with user prompts, inject or delete objects, and mount att
nvd
CVE-2026-103765P2CRITICALCVSS 9.4≤ 0.3.13.post12026-10-02
CVE-2026-103765 [CRITICAL] CWE-306 CVE-2026-103765: Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata s
Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison segment descriptors such as tcp_data_port or re-create rpc_meta entries to redirect KV cache transfers
nvd
CVE-2026-103764P2CRITICALCVSS 9.8fixed in 0.3.132026-10-02
CVE-2026-103764 [CRITICAL] CWE-822 CVE-2026-103764: Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::r
Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or WRITE opcodes to disclose KV c
nvd
CVE-2026-106038P3HIGHCVSS 8.2≤ 0.3.13.post12026-10-06
CVE-2026-106038 [HIGH] CWE-306 CVE-2026-106038: Mooncake Store master through 0.3.13.post1 contains a missing authentication vulnerability that allo
Mooncake Store master through 0.3.13.post1 contains a missing authentication vulnerability that allows unauthenticated attackers to force-delete any object via Remove, RemoveByRegex, RemoveAll and BatchRemove on the coro_rpc port. Attackers can send forged requests with the force flag set to bypass lease checks, wipe keys matching any regex, or clea
nvd
CVE-2026-96762P3HIGHCVSS 7.3v0.3.0v0.3.1+12 more2026-09-24
CVE-2026-96762 [HIGH] CWE-285 CVE-2026-96762: A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the fu
A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegment of the component RPC Path Handler. This manipulation of the argument client_id/segment_id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The
nvd
CVE-2026-106040P3HIGHCVSS 8.2≤ 0.3.13.post12026-10-06
CVE-2026-106040 [HIGH] CWE-862 CVE-2026-106040: Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allow
Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to erase any object's disk replica via EvictDiskReplica and BatchEvictDiskReplica. Attackers reaching the coro_rpc master port can evict DISK replicas across all tenants, deleting objects whose only remaining replica is on
nvd
CVE-2026-104433P3HIGHCVSS 7.5fixed in 0.3.122026-10-03
CVE-2026-104433 [HIGH] CWE-125 CVE-2026-104433: Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readStrin
Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attackers can connect to the handshake port listening on all interfaces and send an eight-byte frame to terminate the h
nvd
CVE-2026-103761P3HIGHCVSS 7.5≤ 0.3.13.post12026-10-01
CVE-2026-103761 [HIGH] CWE-770 CVE-2026-103761: Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in Transfer
Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly send notify frames up to 1 MB to the handshake RPC port, filling the uncapped notifys vector until the out-of-memory kille
nvd
CVE-2026-106041P3MEDIUMCVSS 6.5≤ 0.3.13.post12026-10-06
CVE-2026-106041 [MEDIUM] CWE-862 CVE-2026-106041: Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allow
Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to inject completed LOCAL_DISK replicas through the NotifyOffloadSuccess RPC. Attackers can mount a local disk segment with a self-chosen client UUID, then attach replicas pointing at attacker-controlled endpoints to serv
nvd
CVE-2026-106039P3MEDIUMCVSS 6.5≤ 0.3.13.post12026-10-06
CVE-2026-106039 [MEDIUM] CWE-862 CVE-2026-106039: Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allow
Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to create, steal, and falsely complete replication tasks via the coro_rpc port. Attackers can invoke CreateCopyTask, CreateMoveTask, FetchTasks, and MarkTaskToComplete with victim client UUIDs disclosed by QueryTask to hi
nvd
CVE-2026-103760P3MEDIUMCVSS 5.9≤ 0.3.13.post12026-10-01
CVE-2026-103760 [MEDIUM] CWE-400 CVE-2026-103760: Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows
Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers can send a Metadata request to the handshake RPC port and stall SocketHandShakePlugin's single listener thread in writeFully(), breaking all subseque
nvd
CVE-2026-96763P4MEDIUMCVSS 5.4v0.3.0v0.3.1+13 more2026-09-24
CVE-2026-96763 [MEDIUM] CWE-266 CVE-2026-96763: A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc1. Thi
A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc1. This issue affects the function ScopedSegmentAccess::MountSegment of the file segment.cpp of the component MountSegment Request Processing. Performing a manipulation results in improper access controls. The attack is possible to be carried out remotely.
nvd
CVE-2026-96764P4MEDIUMCVSS 4.3v0.3.0v0.3.1+12 more2026-09-24
CVE-2026-96764 [MEDIUM] CWE-400 CVE-2026-96764: A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1. Impacted is the funct
A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1. Impacted is the function MasterService::GetReplicaListByRegex of the component Regular Expression Handler. Executing a manipulation can lead to allocation of resources. The attack may be performed from remote. The exploit has been made available to the public and could be
nvd