Out-of-Bounds Read Vulnerability in Mooncake Transfer Engine by KVCACHE AI
CVE-2026-104433
8.7HIGH
What is CVE-2026-104433?
The Mooncake Transfer Engine, prior to version 0.3.12, is vulnerable to an out-of-bounds read in the readString function located in include/common.h. This allows unauthenticated attackers to exploit the vulnerability by sending a zero-length handshake frame, potentially leading to a service crash. Attackers can connect to the handshake port that is accessible on all interfaces and transmit an eight-byte frame that disrupts the hosting process, notably affecting services like SGLang inference servers.
Affected Version(s)
Mooncake 0 < 0.3.12
Mooncake 0.3.12
