CVE-2026-103765 is a critical (CVSS 3.1: 9.4) missing-authentication flaw in the Mooncake HTTP metadata server. An unauthenticated attacker can read, overwrite and delete transfer engine metadata, which lets them redirect KV cache transfers or exhaust server memory.
What Is It
The /metadata handler in Mooncake's HTTP metadata server does not require authentication (CWE-306: Missing Authentication for Critical Function). Anyone who can reach the server can read, overwrite and delete transfer engine metadata keys without credentials.
The NVD description says attackers can:
- Poison segment descriptors, such as
tcp_data_port - Re-create
rpc_metaentries to send KV cache transfers to listeners they control - Exhaust the server's memory
VulnCheck reported the flaw. The NVD record's status is currently "Received."
Why It Matters
The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H. An attacker can exploit the flaw over the network with low complexity, no privileges and no user interaction. The impact is high for confidentiality, low for integrity and high for availability. VulnCheck gives it a CVSS 4.0 score of 8.8 (HIGH).
If KV cache transfers are redirected to an attacker's listener, data moving through the transfer engine could be exposed. Memory exhaustion could take the metadata service down. Treat any exposed metadata server as a high-priority risk.
Exploitation status: As of this writing, this CVE is not in the CISA Known Exploited Vulnerabilities (KEV) catalog, and active exploitation has not been confirmed.
What's Vulnerable
- Vendor: kvcache-ai
- Product: Mooncake
- Package:
pkg:pypi/mooncake-transfer-engine - Affected versions: All versions up to and including 0.3.13.post1
The vulnerable code is in the HTTP metadata server implementation, mooncake-wheel/mooncake/http_metadata_server.py. A link is in the sources below.
Patch Status
As of this writing, the NVD record does not name a fixed version. CISA has not listed this CVE in KEV, so there is no CISA required action. Until a fix is confirmed, operators should:
- Watch the upstream GitHub issue and the VulnCheck advisory for a patched release
- Check whether any deployment runs
mooncake-transfer-engine0.3.13.post1 or earlier - Make sure untrusted networks cannot reach the HTTP metadata server