Tools AI Risk Radar ai-incident-0124
Incident record
Mooncake's metadata server lets anyone redirect AI cache transfers
- Severity
- Critical
- Status
- Proof-of-concept
- Type
- Infra Vuln
- Target
- Mooncake (kvcache-ai/Mooncake) through 0.3.13.post1, the current release
- Actor
- researcher
- CVE
- CVE-2026-103765, CVE-2026-103761, CVE-2026-103760
What happened
Mooncake's HTTP metadata server answers its /metadata handler with no authentication, so anyone who can reach it can read, overwrite and delete transfer-engine metadata, poison segment descriptors such as tcp_data_port and redirect KV-cache transfers to a listener they control. CVE-2026-103765, published on 2 October 2026, scores it CVSS 3.1 9.4 and lists every release through 0.3.13.post1, the current one on PyPI, as affected.
Two denial-of-service records published on 1 October affect the same releases: notify frames of up to 1 MB sent to the handshake RPC port grow memory without limit until the out-of-memory killer ends the engine (CVE-2026-103761, 7.5), and a client that never reads replies stalls the handshake daemon's single listener thread (CVE-2026-103760, 5.9). No fixed release was confirmed for the three as of 2 October. SGLang CVE-2026-102634 of 29 September, which crashes SGLang schedulers through duplicate bootstrap_room values on the Mooncake backend, is on row ai-incident-0098.
Sources
- NVD record CVE-2026-103765nvd.nist.gov/vuln/detail/CVE-2026-103765
- NVD record CVE-2026-103761nvd.nist.gov/vuln/detail/CVE-2026-103761
- NVD record CVE-2026-103760nvd.nist.gov/vuln/detail/CVE-2026-103760
- VulnCheck advisory: Mooncake HTTP metadata serverwww.vulncheck.com/advisories/mooncake-through-0.3.13-post1-m…
- Mooncake on PyPIpypi.org/project/mooncake-transfer-engine/
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 2 October 2026