Mooncake 0.3.13.post1 及更早版本中存在一个未认证的漏洞,该漏洞位于 HTTP 元数据服务器 /metadata 处理器中。攻击者无需认证即可读取、覆盖和删除传输引擎的元数据键。攻击者可以毒化段描述符(例如 tcp_data_port)或重新创建 rpc_meta 条目,将 KV 缓存传输重定向到攻击者控制的监听器,或者耗尽服务器内存。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| kvcache-ai | Mooncake | ≤ 0.3.13.post1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kvcache-ai | Mooncake | 0 ~ 0.3.13.post1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103764 | 9.8 CRITICAL | Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP |
| CVE-2026-103761 | 7.5 HIGH | Mooncake transfer engine through 0.3.13.post1 Memory Exhaustion via Unbounded Notify Queue |
| CVE-2026-103760 | 5.9 MEDIUM | Mooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Handshake Daemon R |
No comments yet