Mooncake 0.3.13.post1 及更早版本在 Store REST 服务中存在缺失身份认证的漏洞。该服务在 0.0.0.0 上绑定且未对任何路由进行身份认证。未经身份认证的攻击者可以调用诸如 /api/get、/api/put、/api/remove_all 和 /api/mount 等接口,以读取带有用户提示的缓存键值(KV)数据,注入或删除对象,并挂载攻击者指定的存储段。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kvcache-ai | Mooncake | 0 ~ 0.3.13.post1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106040 | 8.2 HIGH | Mooncake Store through 0.3.13.post1 Missing Authorization via EvictDiskReplica RPC |
| CVE-2026-106038 | 8.2 HIGH | Mooncake Store through 0.3.13.post1 Unauthenticated Object Deletion via Remove RPCs |
| CVE-2026-106041 | 6.5 MEDIUM | Mooncake Store through 0.3.13.post1 Missing Authorization via NotifyOffloadSuccess RPC |
| CVE-2026-106039 | 6.5 MEDIUM | Mooncake Store through 0.3.13.post1 Missing Authorization in Replication Task RPC |
No comments yet