Sceawere
Vulnerability Detail
CVE-2026-103764UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Mooncake Memory Corruption Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 23h ago
- Vendor
- kvcache-ai
- Product
- Mooncake
- Attack Type
- Untrusted Pointer Dereference
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or WRITE opcodes to disclose KV cache contents, prompts and secrets or corrupt memory toward code execution.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-10-02T00:16:59.253Z",
"pubdate": "2026-10-02T00:16:59.253Z",
"executiveSummary": "Mooncake transfer engine versions prior to 0.3.13 are susceptible to an unauthenticated untrusted pointer dereference vulnerability residing within the TCP transport layer.\nThe flaw stems from improper validation of address and size parameters within the SessionHeader processing logic. This enables remote, unauthenticated attackers to perform arbitrary memory read and write operations on the host process.\nThe impact of this vulnerability is critical, as it facilitates the disclosure of sensitive data, such as KV cache contents, user prompts, and cryptographic secrets. Furthermore, the ability to perform arbitrary memory writes allows for memory corruption that can be leveraged to achieve arbitrary code execution.\nThis vulnerability exposes the system to complete compromise. There are no authentication requirements for exploitation, as the flaw is reachable via the TCP transport data port. Organizations utilizing Mooncake versions earlier than 0.3.13 are at significant risk and should prioritize immediate mitigation.",
"technicalDetails": "The vulnerability is located in the ServerSession::readHeader function within the Mooncake transfer engine. The core issue is an untrusted pointer dereference, wherein the application fails to validate the addr and size fields provided in a SessionHeader from an external client. Because the transport layer blindly trusts these values, an attacker can manipulate them to point to arbitrary locations within the process memory space.\nThe attack flow commences when an unauthenticated attacker establishes a TCP connection to the Mooncake transfer engine data port. The attacker transmits a crafted SessionHeader packet. By specifying a READ opcode in the header alongside a malicious addr and size, the attacker forces the engine to read memory contents at the specified location and return the data back over the socket. This mechanism can be used to perform unauthorized memory dumping, effectively bypassing process isolation to extract sensitive KV cache buffers, active prompts, and secrets residing in memory.\nConversely, by utilizing a WRITE opcode, the attacker can supply data to be written into an arbitrary memory address. This capability is exceptionally dangerous, as it allows an attacker to overwrite critical data structures, function pointers, or return addresses in the stack or heap. By carefully crafting the payload, an attacker can redirect the program's control flow, leading to remote code execution (RCE) with the privileges of the service.\nThe vulnerability affects all Mooncake transfer engine deployments versioned prior to 0.3.13. Since the exploit vector is exposed via the TCP transport data port, it does not require authentication or elevated privileges to initiate. The exploit is highly reliable, as it operates at the transport layer, effectively weaponizing the application's intended internal memory management mechanisms against itself. Post-exploitation, an attacker can achieve persistent access or complete exfiltration of proprietary data structures handled by the engine."
}