Mooncake 传输引擎在版本 0.3.13.post1 中存在一个内存耗尽漏洞,位于 函数中,允许未经身份验证的攻击者无限制地增长进程内存。攻击者可以反复向握手 RPC 端口发送最多 1 MB 的通知帧(notify frames),不断填充未设置上限的 notifys 向量,直到触发系统的内存溢出(OOM)终止机制,导致引擎被操作系统强制终止。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kvcache-ai | Mooncake | 0 ~ 0.3.13.post1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103764 | 9.8 CRITICAL | Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP |
| CVE-2026-103765 | 9.4 CRITICAL | Mooncake through 0.3.13.post1 Missing Authentication in HTTP Metadata Server |
| CVE-2026-103760 | 5.9 MEDIUM | Mooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Handshake Daemon R |
No comments yet