All 7 CVE vulnerabilities found in mooncake, with AI-generated Chinese analysis, references, and POCs.
Vendor: kvcache-ai
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-103764 | Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport CWE-822 | 9.8 | Critical | 2026-10-01 |
| CVE-2026-103765 | Mooncake through 0.3.13.post1 Missing Authentication in HTTP Metadata Server CWE-306 | 9.4 | Critical | 2026-10-01 |
| CVE-2026-103761 | Mooncake transfer engine through 0.3.13.post1 Memory Exhaustion via Unbounded Notify Queue CWE-770 | 7.5 | High | 2026-10-01 |
| CVE-2026-103760 | Mooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Handshake Daemon Response Write CWE-400 | 5.9 | Medium | 2026-10-01 |
| CVE-2026-96764 | kvcache-ai mooncake Regular Expression GetReplicaListByRegex allocation of resources CWE-770 | 4.3 | Medium | 2026-09-24 |
| CVE-2026-96763 | kvcache-ai mooncake MountSegment Request Processing segment.cpp access control CWE-284 | 5.4 | Medium | 2026-09-24 |
| CVE-2026-96762 | kvcache-ai mooncake RPC Path UnmountSegment authorization CWE-639 | 7.3 | High | 2026-09-23 |
All 7 known CVE vulnerabilities affecting mooncake with full Chinese analysis, references, and POCs where available.