DEV Community

threataft
threataft

Posted on Originally published at threataft.com

Mooncake Mass Disclosure — CVSS 9.8 Arbitrary Memory Read/Write in KV Cache Transfer Engine

A crafted TCP packet to Mooncake's transfer data port is enough to read and write arbitrary process memory — no authentication required.

CVE-2026-103764 (CVSS 9.8) is an untrusted pointer dereference in ServerSession::readHeader. The readHeader function trusts attacker-supplied addr and size fields in the SessionHeader, making any exposed transfer data port a direct window into process memory.

CVE-2026-103765 (CVSS 9.4) is a missing authentication flaw in the HTTP metadata server's /metadata handler. Attackers can poison segment descriptors like tcp_data_port or re-create rpc_meta entries to redirect KV cache transfers to attacker-controlled listeners.

Two more: CVE-2026-103761 (CVSS 7.5) enables unbounded memory growth via uncapped notify frames. CVE-2026-103760 (CVSS 5.9) stalls the single-threaded handshake daemon by never reading a reply.

Patch status: CVE-2026-103764 is fixed in Mooncake 0.3.13. The other three affect versions through 0.3.13.post1 — no fix confirmed yet.

Compensating control: Firewall the TCP data port, handshake RPC port, and HTTP metadata server to trusted nodes only.

Full breakdown → https://threataft.com/articles/mooncake-mass-disclosure-cve-2026-103764-103765-103761-103760

Top comments (0)