Mooncake Mass Disclosure — CVSS 9.8 Arbitrary Memory Read/Write in KV Cache Transfer Engine
A crafted TCP packet to Mooncake's transfer data port is enough to read and write arbitrary process memory — no authentication required. CVE-2026-103764 (CVSS 9.8) is an untrusted pointer dereference in ServerSession::readHeader. The readHeader function trusts attacker-supplied addr and size fields…
Read the full story at DEV Community — Machine Learning ↗
Timeline · 1 report
- 2026-10-02 03:15 · DEV Community — Machine Learning
Mooncake Mass Disclosure — CVSS 9.8 Arbitrary Memory Read/Write in KV Cache Transfer Engine