A critical untrusted pointer dereference in the Mooncake transfer engine before version 0.3.13 lets unauthenticated remote attackers read and write arbitrary process memory over the TCP transport data port.
What Is It
CVE-2026-103764 is an untrusted pointer dereference (CWE-822) in the ServerSession::readHeader function of kvcache-ai's Mooncake transfer engine. An attacker can send a crafted SessionHeader with any addr and size values they choose, using the READ or WRITE opcodes. The server then reads from or writes to those memory locations within its own process.
VulnCheck reported the issue. NVD lists it with a status of "Received."
Why It Matters
The flaw is scored CVSS 3.1 9.8 (Critical) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, and CVSS 4.0 9.3 (Critical). The attacker needs no authentication and no user interaction, and the attack is low-complexity and network-reachable.
According to the advisory description: - Arbitrary memory reads can expose KV cache contents, prompts and secrets held in the process. - Arbitrary memory writes can corrupt memory toward code execution.
Mooncake moves KV cache data for large language model serving, so a compromised instance could expose user prompts and model inference data as well as credentials.
Exploitation status: No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed by KEV at this time.
What's Vulnerable
- Vendor: kvcache-ai
- Product: Mooncake (transfer engine)
- Package:
pkg:pypi/mooncake-transfer-engine - Affected versions: all versions before 0.3.13
- Attack surface: the TCP transport data port
No CPE entries were listed in the NVD record.
Patch Status
A fix is available in Mooncake v0.3.13. The NVD references link the v0.3.13 release and a fixing commit (a2933849). Organizations running mooncake-transfer-engine should upgrade to 0.3.13 or later. Because the attack comes in over the network without authentication, defenders should also check whether TCP transport data ports are reachable from untrusted networks.
No CISA-mandated required action or due date applies, since this CVE has no KEV entry.