Mooncake 传输引擎在 0.3.13 版本之前存在一个不受信任的指针解引用漏洞,该漏洞位于 函数中,允许未经身份验证的攻击者通过 TCP 传输数据端口读取和写入任意进程内存。攻击者可以使用带有任意 和 值的伪造 ,并通过 或 操作码来泄露 KV 缓存内容、提示词和密钥信息,或者破坏内存以达成代码执行的目的。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| kvcache-ai | Mooncake | < 0.3.13 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kvcache-ai | Mooncake | 0 ~ 0.3.13 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103765 | 9.4 CRITICAL | Mooncake through 0.3.13.post1 Missing Authentication in HTTP Metadata Server |
| CVE-2026-103761 | 7.5 HIGH | Mooncake transfer engine through 0.3.13.post1 Memory Exhaustion via Unbounded Notify Queue |
| CVE-2026-103760 | 5.9 MEDIUM | Mooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Handshake Daemon R |
No comments yet