A crafted TCP packet to Mooncake's transfer data port is enough to read and write arbitrary process memory — no authentication required.
CVE-2026-103764 (CVSS 9.8) is an untrusted pointer dereference in ServerSession::readHeader. The readHeader function trusts attacker-supplied addr and size fields in the SessionHeader, making any exposed transfer data port a direct window into process memory.
CVE-2026-103765 (CVSS 9.4) is a missing authentication flaw in the HTTP metadata server's /metadata handler. Attackers can poison segment descriptors like tcp_data_port or re-create rpc_meta entries to redirect KV cache transfers to attacker-controlled listeners.
Two more: CVE-2026-103761 (CVSS 7.5) enables unbounded memory growth via uncapped notify frames. CVE-2026-103760 (CVSS 5.9) stalls the single-threaded handshake daemon by never reading a reply.
Patch status: CVE-2026-103764 is fixed in Mooncake 0.3.13. The other three affect versions through 0.3.13.post1 — no fix confirmed yet.
Compensating control: Firewall the TCP data port, handshake RPC port, and HTTP metadata server to trusted nodes only.
Full breakdown → https://threataft.com/articles/mooncake-mass-disclosure-cve-2026-103764-103765-103761-103760
Top comments (0)