Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-103761— Mooncake transfer engine through 0.3.13.post1 Memory Exhaustion via Unbounded Notify Queue

Quick assessment

Affected
kvcache-ai Mooncake
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Mooncake 传输引擎在版本 0.3.13.post1 中存在一个内存耗尽漏洞,位于 函数中,允许未经身份验证的攻击者无限制地增长进程内存。攻击者可以反复向握手 RPC 端口发送最多 1 MB 的通知帧(notify frames),不断填充未设置上限的 notifys 向量,直到触发系统的内存溢出(OOM)终止机制,导致引擎被操作系统强制终止。

CVSS 7.5 · High

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-103761

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Mooncake transfer engine through 0.3.13.post1 Memory Exhaustion via Unbounded Notify Queue
Source: CVE Program / CVE List V5
Vulnerability Description
Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly send notify frames up to 1 MB to the handshake RPC port, filling the uncapped notifys vector until the out-of-memory killer terminates the engine.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
kvcache-ai Mooncake 0 ~ 0.3.13.post1 -

II. Public POCs for CVE-2026-103761

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-103761

请登录查看更多情报信息。

Other References for CVE-2026-103761 (4)

Same Patch Batch · kvcache-ai · 2026-10-01 · 4 CVEs total

CVE-2026-103764 9.8 CRITICAL Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP
CVE-2026-103765 9.4 CRITICAL Mooncake through 0.3.13.post1 Missing Authentication in HTTP Metadata Server
CVE-2026-103760 5.9 MEDIUM Mooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Handshake Daemon R

IV. Related Vulnerabilities

V. Comments for CVE-2026-103761

No comments yet


Leave a comment