CVE & Vulnerabilities · October 5, 2026
CVE-2026-104433 is an out-of-bounds read flaw in the Mooncake transfer engine, affecting versions before 0.3.12, inside the readString parsing routine. Because the handshake port listens on every network interface, an unauthenticated attacker can connect and send a malformed, zero-length frame to kill the process, notably impacting AI inference servers like SGLang that rely on Mooncake. Upgrading past the fixed version closes the hole.
// source: nvd.nist.gov ↗