YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0124

Incident record

Mooncake's metadata server lets anyone redirect AI cache transfers

Severity
Critical
Status
Proof-of-concept
Type
Infra Vuln
Target
Mooncake (kvcache-ai/Mooncake) through 0.3.13.post1, the current release
Actor
researcher
CVE
CVE-2026-103765, CVE-2026-103761, CVE-2026-103760

What happened

Mooncake's HTTP metadata server answers its /metadata handler with no authentication, so anyone who can reach it can read, overwrite and delete transfer-engine metadata, poison segment descriptors such as tcp_data_port and redirect KV-cache transfers to a listener they control. CVE-2026-103765, published on 2 October 2026, scores it CVSS 3.1 9.4 and lists every release through 0.3.13.post1, the current one on PyPI, as affected.

Two denial-of-service records published on 1 October affect the same releases: notify frames of up to 1 MB sent to the handshake RPC port grow memory without limit until the out-of-memory killer ends the engine (CVE-2026-103761, 7.5), and a client that never reads replies stalls the handshake daemon's single listener thread (CVE-2026-103760, 5.9). No fixed release was confirmed for the three as of 2 October. SGLang CVE-2026-102634 of 29 September, which crashes SGLang schedulers through duplicate bootstrap_room values on the Mooncake backend, is on row ai-incident-0098.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 2 October 2026