CVE-2026-103764: Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport

Published Oct 1, 2026
·
Updated

Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or WRITE opcodes to disclose KV cache contents, prompts and secrets or corrupt memory toward code execution.

Affected Software

1 affected component
Mooncake Mooncake transfer engine<0.3.13

Event History

Oct 1, 2026
CVE Published
via MITRE·11:19 PM
Data Sourced
via MITRE·11:19 PM
DescriptionSeverityWeakness
Oct 2, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to remote exploitation?

Deployments running Mooncake transfer engine versions before 0.3.13 are exposed if an attacker can reach the TCP transport data port. Exploitation does not require authentication, privileges, or user interaction.

2

What does an attacker need to send to exploit the issue?

An attacker can send a crafted SessionHeader containing attacker-controlled addr and size values and use READ or WRITE opcodes. This can read arbitrary process memory or corrupt it, potentially leading to code execution.

3

What information or systems could be affected?

Successful reads can disclose KV cache contents, prompts, and secrets held in process memory. Successful writes can corrupt process memory and may be used to pursue code execution.

4

What should be done to remediate the issue?

Upgrade the Mooncake transfer engine to version 0.3.13 or later. If an upgrade cannot be performed immediately, restrict network access to the TCP transport data port to prevent untrusted hosts from reaching it.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203