Out-of-Bounds Read Vulnerability in Mooncake Transfer Engine by KVCACHE AI
CVE-2026-104433

8.7HIGH

Key Information:

Vendor

Kvcache-ai

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104433?

The Mooncake Transfer Engine, prior to version 0.3.12, is vulnerable to an out-of-bounds read in the readString function located in include/common.h. This allows unauthenticated attackers to exploit the vulnerability by sending a zero-length handshake frame, potentially leading to a service crash. Attackers can connect to the handshake port that is accessible on all interfaces and transmit an eight-byte frame that disrupts the hosting process, notably affecting services like SGLang inference servers.

Affected Version(s)

Mooncake 0 < 0.3.12

Mooncake 0.3.12

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mingkai Yu
Xiangjun Sun
Jiajia Liu
.