Tools AI Risk Radar ai-incident-0123
Incident record
Anyone could read and write Mooncake's memory over the network
- Severity
- Critical
- Status
- Patched
- Type
- Infra Vuln
- Target
- Mooncake transfer engine (kvcache-ai/Mooncake) before 0.3.13, the KV-cache transfer layer used for disaggregated serving with vLLM and SGLang
- Actor
- researcher
- CVE
- CVE-2026-103764
What happened
Mooncake's transfer engine, which moves KV-cache data between servers in disaggregated AI inference, trusted the address and size fields in a TCP SessionHeader before version 0.3.13. An unauthenticated attacker who could reach the TCP transport data port could read and write arbitrary process memory, disclosing KV-cache contents, prompts and secrets or corrupting memory toward code execution. CVE-2026-103764, published on 2 October 2026, scores it CVSS 3.1 9.8.
Mooncake 0.3.13, released on PyPI on 26 August 2026, carries the fix. Three more Mooncake records published on 1 and 2 October affect the current 0.3.13.post1 release and sit on their own row.
Sources
- NVD record CVE-2026-103764nvd.nist.gov/vuln/detail/CVE-2026-103764
- VulnCheck advisory: Mooncake arbitrary memory read and writewww.vulncheck.com/advisories/mooncake-transfer-engine-before…
- Mooncake v0.3.13 releasegithub.com/kvcache-ai/Mooncake/releases/tag/v0.3.13
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 2 October 2026