CVE-2026-103764

CVE & Vulnerabilities · October 4, 2026

CVE & Vulnerabilities·nvd.nist.gov

A newly disclosed bug in the Mooncake transfer engine, affecting versions before 0.3.13, stems from an unchecked pointer dereference in how the server handles session headers on its TCP data channel. Because no authentication is required, an attacker can send a forged header with chosen address and size values to read sensitive KV cache contents and prompts, or corrupt memory in a way that could lead to code execution.

// source: nvd.nist.gov ↗

← Back to Blog