YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0123

Incident record

Anyone could read and write Mooncake's memory over the network

Severity
Critical
Status
Patched
Type
Infra Vuln
Target
Mooncake transfer engine (kvcache-ai/Mooncake) before 0.3.13, the KV-cache transfer layer used for disaggregated serving with vLLM and SGLang
Actor
researcher
CVE
CVE-2026-103764

What happened

Mooncake's transfer engine, which moves KV-cache data between servers in disaggregated AI inference, trusted the address and size fields in a TCP SessionHeader before version 0.3.13. An unauthenticated attacker who could reach the TCP transport data port could read and write arbitrary process memory, disclosing KV-cache contents, prompts and secrets or corrupting memory toward code execution. CVE-2026-103764, published on 2 October 2026, scores it CVSS 3.1 9.8.

Mooncake 0.3.13, released on PyPI on 26 August 2026, carries the fix. Three more Mooncake records published on 1 and 2 October affect the current 0.3.13.post1 release and sit on their own row.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 2 October 2026