Mooncake传输引擎版本0.3.13.post1之前存在一个拒绝服务漏洞,该漏洞允许未经身份验证的远程攻击者通过不读取响应来阻塞握手守护进程。攻击者可以向握手RPC端口发送Metadata请求,并阻止SocketHandShakePlugin中的单个监听线程在writeFully()函数中停滞,从而破坏所有后续的握手、元数据获取、通知和探测请求。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| kvcache-ai | Mooncake | ≤ 0.3.13.post1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kvcache-ai | Mooncake | 0 ~ 0.3.13.post1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103764 | 9.8 CRITICAL | Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP |
| CVE-2026-103765 | 9.4 CRITICAL | Mooncake through 0.3.13.post1 Missing Authentication in HTTP Metadata Server |
| CVE-2026-103761 | 7.5 HIGH | Mooncake transfer engine through 0.3.13.post1 Memory Exhaustion via Unbounded Notify Queue |
No comments yet