CVE-2026-103764: Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport
Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or WRITE opcodes to disclose KV cache contents, prompts and secrets or corrupt memory toward code execution.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to remote exploitation?
Deployments running Mooncake transfer engine versions before 0.3.13 are exposed if an attacker can reach the TCP transport data port. Exploitation does not require authentication, privileges, or user interaction.
What does an attacker need to send to exploit the issue?
An attacker can send a crafted SessionHeader containing attacker-controlled addr and size values and use READ or WRITE opcodes. This can read arbitrary process memory or corrupt it, potentially leading to code execution.
What information or systems could be affected?
Successful reads can disclose KV cache contents, prompts, and secrets held in process memory. Successful writes can corrupt process memory and may be used to pursue code execution.
What should be done to remediate the issue?
Upgrade the Mooncake transfer engine to version 0.3.13 or later. If an upgrade cannot be performed immediately, restrict network access to the TCP transport data port to prevent untrusted hosts from reaching it.