Search

Find a vulnerability

Search criteria

    14 vulnerabilities found for mooncake by kvcache-ai

    CVE-2026-103765 (GCVE-0-2026-103765)

    Vulnerability from nvd – Published: 2026-10-01 23:19 – Updated: 2026-10-01 23:19
    VLAI
    Title
    Mooncake through 0.3.13.post1 Missing Authentication in HTTP Metadata Server
    Summary
    Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison segment descriptors such as tcp_data_port or re-create rpc_meta entries to redirect KV cache transfers to attacker-controlled listeners, or exhaust server memory.
    CWE
    • CWE-306 - Missing Authentication for Critical Function
    Impacted products
    Vendor Product Version
    kvcache-ai Mooncake Affected: 0 , ≤ 0.3.13.post1 (custom)
    Create a notification for this product.
    Date Public
    2026-10-01 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:pypi/mooncake-transfer-engine",
              "product": "Mooncake",
              "vendor": "kvcache-ai",
              "versions": [
                {
                  "lessThanOrEqual": "0.3.13.post1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Mingkai Yu"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Jiajia Liu"
            }
          ],
          "datePublic": "2026-10-01T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison segment descriptors such as tcp_data_port or re-create rpc_meta entries to redirect KV cache transfers to attacker-controlled listeners, or exhaust server memory."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.4,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "Missing Authentication for Critical Function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T23:19:58.492Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Issue #4444",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake/issues/4444"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake/blob/719735896c86b56fabec6cf3e825fb2ea640597a/mooncake-wheel/mooncake/http_metadata_server.py#L61-L106"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake"
            },
            {
              "name": "VulnCheck Advisory: Mooncake through 0.3.13.post1 Missing Authentication in HTTP Metadata Server",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/mooncake-through-0.3.13-post1-missing-authentication-in-http-metadata-server"
            }
          ],
          "title": "Mooncake through 0.3.13.post1 Missing Authentication in HTTP Metadata Server",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-103765",
        "datePublished": "2026-10-01T23:19:58.492Z",
        "dateReserved": "2026-10-01T10:39:47.845Z",
        "dateUpdated": "2026-10-01T23:19:58.492Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-103764 (GCVE-0-2026-103764)

    Vulnerability from nvd – Published: 2026-10-01 23:19 – Updated: 2026-10-01 23:19
    VLAI
    Title
    Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport
    Summary
    Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or WRITE opcodes to disclose KV cache contents, prompts and secrets or corrupt memory toward code execution.
    CWE
    • CWE-822 - Untrusted Pointer Dereference
    Impacted products
    Vendor Product Version
    kvcache-ai Mooncake Affected: 0 , < 0.3.13 (custom)
    Create a notification for this product.
    Date Public
    2026-10-01 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:pypi/mooncake-transfer-engine",
              "product": "Mooncake",
              "vendor": "kvcache-ai",
              "versions": [
                {
                  "lessThan": "0.3.13",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Mingkai Yu"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Jiajia Liu"
            }
          ],
          "datePublic": "2026-10-01T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or WRITE opcodes to disclose KV cache contents, prompts and secrets or corrupt memory toward code execution."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-822",
                  "description": "Untrusted Pointer Dereference",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T23:19:57.849Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Issue #4441",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake/issues/4441"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake/commit/a2933849417259e562fc9cbad63c618d464dfb2d"
            },
            {
              "name": "Mooncake v0.3.13 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake/releases/tag/v0.3.13"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake/blob/6041a609a8c3af35e778f70db344f145c2914980/mooncake-transfer-engine/src/transport/tcp_transport/tcp_transport.cpp#L209"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake"
            },
            {
              "name": "VulnCheck Advisory: Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/mooncake-transfer-engine-before-0.3.13-unauthenticated-arbitrary-memory-read-write-via-tcp-transport"
            }
          ],
          "title": "Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-103764",
        "datePublished": "2026-10-01T23:19:57.849Z",
        "dateReserved": "2026-10-01T10:39:47.845Z",
        "dateUpdated": "2026-10-01T23:19:57.849Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-103761 (GCVE-0-2026-103761)

    Vulnerability from nvd – Published: 2026-10-01 22:53 – Updated: 2026-10-01 22:53
    VLAI
    Title
    Mooncake transfer engine through 0.3.13.post1 Memory Exhaustion via Unbounded Notify Queue
    Summary
    Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly send notify frames up to 1 MB to the handshake RPC port, filling the uncapped notifys vector until the out-of-memory killer terminates the engine.
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    Impacted products
    Vendor Product Version
    kvcache-ai Mooncake Affected: 0 , ≤ 0.3.13.post1 (custom)
    Create a notification for this product.
    Date Public
    2026-10-01 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:pypi/mooncake-transfer-engine",
              "product": "Mooncake",
              "vendor": "kvcache-ai",
              "versions": [
                {
                  "lessThanOrEqual": "0.3.13.post1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Mingkai Yu"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Jiajia Liu"
            }
          ],
          "datePublic": "2026-10-01T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly send notify frames up to 1 MB to the handshake RPC port, filling the uncapped notifys vector until the out-of-memory killer terminates the engine."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T22:53:06.016Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Issue #4445",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake/issues/4445"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake/blob/719735896c86b56fabec6cf3e825fb2ea640597a/mooncake-transfer-engine/src/transfer_metadata.cpp#L285-L296"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake"
            },
            {
              "name": "VulnCheck Advisory: Mooncake transfer engine through 0.3.13.post1 Memory Exhaustion via Unbounded Notify Queue",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/mooncake-transfer-engine-through-0.3.13-post1-memory-exhaustion-via-unbounded-notify-queue"
            }
          ],
          "title": "Mooncake transfer engine through 0.3.13.post1 Memory Exhaustion via Unbounded Notify Queue",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-103761",
        "datePublished": "2026-10-01T22:53:06.016Z",
        "dateReserved": "2026-10-01T10:39:47.845Z",
        "dateUpdated": "2026-10-01T22:53:06.016Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-103760 (GCVE-0-2026-103760)

    Vulnerability from nvd – Published: 2026-10-01 22:53 – Updated: 2026-10-01 22:53
    VLAI
    Title
    Mooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Handshake Daemon Response Write
    Summary
    Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers can send a Metadata request to the handshake RPC port and stall SocketHandShakePlugin's single listener thread in writeFully(), breaking all subsequent handshakes, metadata fetches, notify and probe requests.
    CWE
    • CWE-400 - Uncontrolled Resource Consumption
    Impacted products
    Vendor Product Version
    kvcache-ai Mooncake Affected: 0 , ≤ 0.3.13.post1 (custom)
    Create a notification for this product.
    Date Public
    2026-10-01 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:pypi/mooncake-transfer-engine",
              "product": "Mooncake",
              "vendor": "kvcache-ai",
              "versions": [
                {
                  "lessThanOrEqual": "0.3.13.post1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Mingkai Yu"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Jiajia Liu"
            }
          ],
          "datePublic": "2026-10-01T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers can send a Metadata request to the handshake RPC port and stall SocketHandShakePlugin\u0027s single listener thread in writeFully(), breaking all subsequent handshakes, metadata fetches, notify and probe requests."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 8.2,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": "Uncontrolled Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T22:53:05.201Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Issue #4443",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake/issues/4443"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake/blob/719735896c86b56fabec6cf3e825fb2ea640597a/mooncake-transfer-engine/src/transfer_metadata_plugin.cpp#L730-L803"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake"
            },
            {
              "name": "VulnCheck Advisory: Mooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Handshake Daemon Response Write",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/mooncake-transfer-engine-through-0.3.13-post1-denial-of-service-via-p2p-handshake-daemon-response-write"
            }
          ],
          "title": "Mooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Handshake Daemon Response Write",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-103760",
        "datePublished": "2026-10-01T22:53:05.201Z",
        "dateReserved": "2026-10-01T10:39:47.845Z",
        "dateUpdated": "2026-10-01T22:53:05.201Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-96764 (GCVE-0-2026-96764)

    Vulnerability from nvd – Published: 2026-09-24 00:15 – Updated: 2026-09-24 14:33
    VLAI
    Title
    kvcache-ai mooncake Regular Expression GetReplicaListByRegex allocation of resources
    Summary
    A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1. Impacted is the function MasterService::GetReplicaListByRegex of the component Regular Expression Handler. Executing a manipulation can lead to allocation of resources. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-24 14:33 UTC
    CWE
    References
    URL Tags
    https://vuldb.com/vuln/409019 vdb-entrytechnical-description
    https://vuldb.com/vuln/409019/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-96764 third-party-advisory
    https://vuldb.com/submit/904607 third-party-advisory
    https://gist.github.com/yyymk/4699cc95ab9a559ee15… exploit
    Impacted products
    Vendor Product Version
    kvcache-ai mooncake Affected: 0.3.0
    Affected: 0.3.1
    Affected: 0.3.2
    Affected: 0.3.3
    Affected: 0.3.4
    Affected: 0.3.5
    Affected: 0.3.6
    Affected: 0.3.7
    Affected: 0.3.8
    Affected: 0.3.9
    Affected: 0.3.10
    Affected: 0.3.11
    Affected: 0.3.12
    Affected: 0.3.14-rc1
        cpe:2.3:a:kvcache-ai:mooncake:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-96764",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-24T14:33:17.401895Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-24T14:33:28.453Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:kvcache-ai:mooncake:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Regular Expression Handler"
              ],
              "product": "mooncake",
              "vendor": "kvcache-ai",
              "versions": [
                {
                  "status": "affected",
                  "version": "0.3.0"
                },
                {
                  "status": "affected",
                  "version": "0.3.1"
                },
                {
                  "status": "affected",
                  "version": "0.3.2"
                },
                {
                  "status": "affected",
                  "version": "0.3.3"
                },
                {
                  "status": "affected",
                  "version": "0.3.4"
                },
                {
                  "status": "affected",
                  "version": "0.3.5"
                },
                {
                  "status": "affected",
                  "version": "0.3.6"
                },
                {
                  "status": "affected",
                  "version": "0.3.7"
                },
                {
                  "status": "affected",
                  "version": "0.3.8"
                },
                {
                  "status": "affected",
                  "version": "0.3.9"
                },
                {
                  "status": "affected",
                  "version": "0.3.10"
                },
                {
                  "status": "affected",
                  "version": "0.3.11"
                },
                {
                  "status": "affected",
                  "version": "0.3.12"
                },
                {
                  "status": "affected",
                  "version": "0.3.14-rc1"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "YYYMK (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1. Impacted is the function MasterService::GetReplicaListByRegex of the component Regular Expression Handler. Executing a manipulation can lead to allocation of resources. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 4,
                "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "Allocation of Resources",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": "Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-24T00:15:12.968Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-409019 | kvcache-ai mooncake Regular Expression GetReplicaListByRegex allocation of resources",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/409019"
            },
            {
              "name": "VDB-409019 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/409019/cti"
            },
            {
              "name": "CVE-2026-96764 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-96764"
            },
            {
              "name": "Submit #904607 | kvcache-ai mooncake \u003e= 0.3.4, \u003c= 0.3.12 Denial of Service",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/904607"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://gist.github.com/yyymk/4699cc95ab9a559ee15a0fb798bd6c5d"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-23T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-23T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-23T18:06:38.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "kvcache-ai mooncake Regular Expression GetReplicaListByRegex allocation of resources",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-96764",
        "datePublished": "2026-09-24T00:15:12.968Z",
        "dateReserved": "2026-09-23T16:01:24.847Z",
        "dateUpdated": "2026-09-24T14:33:28.453Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-96763 (GCVE-0-2026-96763)

    Vulnerability from nvd – Published: 2026-09-24 00:00 – Updated: 2026-09-29 02:41
    VLAI
    Title
    kvcache-ai mooncake MountSegment Request Processing segment.cpp access control
    Summary
    A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc1. This issue affects the function ScopedSegmentAccess::MountSegment of the file segment.cpp of the component MountSegment Request Processing. Performing a manipulation results in improper access controls. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 02:41 UTC
    CWE
    • CWE-284 - Improper Access Controls
    • CWE-266 - Incorrect Privilege Assignment
    References
    URL Tags
    https://vuldb.com/vuln/409018 vdb-entrytechnical-description
    https://vuldb.com/vuln/409018/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-96763 third-party-advisory
    https://vuldb.com/submit/904605 third-party-advisory
    https://gist.github.com/yyymk/fea24846dc31042cb47… exploit
    Impacted products
    Vendor Product Version
    kvcache-ai mooncake Affected: 0.3.0
    Affected: 0.3.1
    Affected: 0.3.2
    Affected: 0.3.3
    Affected: 0.3.4
    Affected: 0.3.5
    Affected: 0.3.6
    Affected: 0.3.7
    Affected: 0.3.8
    Affected: 0.3.9
    Affected: 0.3.10
    Affected: 0.3.11
    Affected: 0.3.12
    Affected: 0.3.13.post1
    Affected: 0.3.14-rc1
        cpe:2.3:a:kvcache-ai:mooncake:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-96763",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T02:41:13.416455Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T02:41:22.511Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:kvcache-ai:mooncake:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "MountSegment Request Processing"
              ],
              "product": "mooncake",
              "vendor": "kvcache-ai",
              "versions": [
                {
                  "status": "affected",
                  "version": "0.3.0"
                },
                {
                  "status": "affected",
                  "version": "0.3.1"
                },
                {
                  "status": "affected",
                  "version": "0.3.2"
                },
                {
                  "status": "affected",
                  "version": "0.3.3"
                },
                {
                  "status": "affected",
                  "version": "0.3.4"
                },
                {
                  "status": "affected",
                  "version": "0.3.5"
                },
                {
                  "status": "affected",
                  "version": "0.3.6"
                },
                {
                  "status": "affected",
                  "version": "0.3.7"
                },
                {
                  "status": "affected",
                  "version": "0.3.8"
                },
                {
                  "status": "affected",
                  "version": "0.3.9"
                },
                {
                  "status": "affected",
                  "version": "0.3.10"
                },
                {
                  "status": "affected",
                  "version": "0.3.11"
                },
                {
                  "status": "affected",
                  "version": "0.3.12"
                },
                {
                  "status": "affected",
                  "version": "0.3.13.post1"
                },
                {
                  "status": "affected",
                  "version": "0.3.14-rc1"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "YYYMK (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc1. This issue affects the function ScopedSegmentAccess::MountSegment of the file segment.cpp of the component MountSegment Request Processing. Performing a manipulation results in improper access controls. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 6.4,
                "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "Improper Access Controls",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-266",
                  "description": "Incorrect Privilege Assignment",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-24T00:00:16.519Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-409018 | kvcache-ai mooncake MountSegment Request Processing segment.cpp access control",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/409018"
            },
            {
              "name": "VDB-409018 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/409018/cti"
            },
            {
              "name": "CVE-2026-96763 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-96763"
            },
            {
              "name": "Submit #904605 | kvcache-ai mooncake mooncake-transfer-engine==0.3.11.post1 Access Control",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/904605"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://gist.github.com/yyymk/fea24846dc31042cb472d7bd496a8438"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-23T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-23T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-23T18:06:34.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "kvcache-ai mooncake MountSegment Request Processing segment.cpp access control",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-96763",
        "datePublished": "2026-09-24T00:00:16.519Z",
        "dateReserved": "2026-09-23T16:01:21.340Z",
        "dateUpdated": "2026-09-29T02:41:22.511Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-96762 (GCVE-0-2026-96762)

    Vulnerability from nvd – Published: 2026-09-23 23:45 – Updated: 2026-09-24 13:18
    VLAI
    Title
    kvcache-ai mooncake RPC Path UnmountSegment authorization
    Summary
    A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegment of the component RPC Path Handler. This manipulation of the argument client_id/segment_id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-24 13:17 UTC
    CWE
    References
    URL Tags
    https://vuldb.com/vuln/409016 vdb-entrytechnical-description
    https://vuldb.com/vuln/409016/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-96762 third-party-advisory
    https://vuldb.com/submit/904600 third-party-advisory
    https://gist.github.com/yyymk/76d099537af0e661dd0… exploit
    Impacted products
    Vendor Product Version
    kvcache-ai mooncake Affected: 0.3.0
    Affected: 0.3.1
    Affected: 0.3.2
    Affected: 0.3.3
    Affected: 0.3.4
    Affected: 0.3.5
    Affected: 0.3.6
    Affected: 0.3.7
    Affected: 0.3.8
    Affected: 0.3.9
    Affected: 0.3.10
    Affected: 0.3.11
    Affected: 0.3.12
    Affected: 0.3.13.post1
        cpe:2.3:a:kvcache-ai:mooncake:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-96762",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-24T13:17:42.616673Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-24T13:18:16.683Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:kvcache-ai:mooncake:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "RPC Path Handler"
              ],
              "product": "mooncake",
              "vendor": "kvcache-ai",
              "versions": [
                {
                  "status": "affected",
                  "version": "0.3.0"
                },
                {
                  "status": "affected",
                  "version": "0.3.1"
                },
                {
                  "status": "affected",
                  "version": "0.3.2"
                },
                {
                  "status": "affected",
                  "version": "0.3.3"
                },
                {
                  "status": "affected",
                  "version": "0.3.4"
                },
                {
                  "status": "affected",
                  "version": "0.3.5"
                },
                {
                  "status": "affected",
                  "version": "0.3.6"
                },
                {
                  "status": "affected",
                  "version": "0.3.7"
                },
                {
                  "status": "affected",
                  "version": "0.3.8"
                },
                {
                  "status": "affected",
                  "version": "0.3.9"
                },
                {
                  "status": "affected",
                  "version": "0.3.10"
                },
                {
                  "status": "affected",
                  "version": "0.3.11"
                },
                {
                  "status": "affected",
                  "version": "0.3.12"
                },
                {
                  "status": "affected",
                  "version": "0.3.13.post1"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "YYYMK (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegment of the component RPC Path Handler. This manipulation of the argument client_id/segment_id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 7.5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "Authorization Bypass",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-285",
                  "description": "Improper Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-23T23:45:14.276Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-409016 | kvcache-ai mooncake RPC Path UnmountSegment authorization",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/409016"
            },
            {
              "name": "VDB-409016 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/409016/cti"
            },
            {
              "name": "CVE-2026-96762 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-96762"
            },
            {
              "name": "Submit #904600 | kvcache-ai Mooncake \u003e= 0.3.4, \u003c= 0.3.12 Authorization Bypass",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/904600"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://gist.github.com/yyymk/76d099537af0e661dd01eacc82b9a7ea"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-23T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-23T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-23T18:06:31.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "kvcache-ai mooncake RPC Path UnmountSegment authorization",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-96762",
        "datePublished": "2026-09-23T23:45:14.276Z",
        "dateReserved": "2026-09-23T16:01:17.341Z",
        "dateUpdated": "2026-09-24T13:18:16.683Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-103765 (GCVE-0-2026-103765)

    Vulnerability from cvelistv5 – Published: 2026-10-01 23:19 – Updated: 2026-10-01 23:19
    VLAI
    Title
    Mooncake through 0.3.13.post1 Missing Authentication in HTTP Metadata Server
    Summary
    Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison segment descriptors such as tcp_data_port or re-create rpc_meta entries to redirect KV cache transfers to attacker-controlled listeners, or exhaust server memory.
    CWE
    • CWE-306 - Missing Authentication for Critical Function
    Impacted products
    Vendor Product Version
    kvcache-ai Mooncake Affected: 0 , ≤ 0.3.13.post1 (custom)
    Create a notification for this product.
    Date Public
    2026-10-01 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:pypi/mooncake-transfer-engine",
              "product": "Mooncake",
              "vendor": "kvcache-ai",
              "versions": [
                {
                  "lessThanOrEqual": "0.3.13.post1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Mingkai Yu"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Jiajia Liu"
            }
          ],
          "datePublic": "2026-10-01T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison segment descriptors such as tcp_data_port or re-create rpc_meta entries to redirect KV cache transfers to attacker-controlled listeners, or exhaust server memory."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.4,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "Missing Authentication for Critical Function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T23:19:58.492Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Issue #4444",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake/issues/4444"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake/blob/719735896c86b56fabec6cf3e825fb2ea640597a/mooncake-wheel/mooncake/http_metadata_server.py#L61-L106"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake"
            },
            {
              "name": "VulnCheck Advisory: Mooncake through 0.3.13.post1 Missing Authentication in HTTP Metadata Server",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/mooncake-through-0.3.13-post1-missing-authentication-in-http-metadata-server"
            }
          ],
          "title": "Mooncake through 0.3.13.post1 Missing Authentication in HTTP Metadata Server",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-103765",
        "datePublished": "2026-10-01T23:19:58.492Z",
        "dateReserved": "2026-10-01T10:39:47.845Z",
        "dateUpdated": "2026-10-01T23:19:58.492Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-103764 (GCVE-0-2026-103764)

    Vulnerability from cvelistv5 – Published: 2026-10-01 23:19 – Updated: 2026-10-01 23:19
    VLAI
    Title
    Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport
    Summary
    Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or WRITE opcodes to disclose KV cache contents, prompts and secrets or corrupt memory toward code execution.
    CWE
    • CWE-822 - Untrusted Pointer Dereference
    Impacted products
    Vendor Product Version
    kvcache-ai Mooncake Affected: 0 , < 0.3.13 (custom)
    Create a notification for this product.
    Date Public
    2026-10-01 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:pypi/mooncake-transfer-engine",
              "product": "Mooncake",
              "vendor": "kvcache-ai",
              "versions": [
                {
                  "lessThan": "0.3.13",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Mingkai Yu"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Jiajia Liu"
            }
          ],
          "datePublic": "2026-10-01T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or WRITE opcodes to disclose KV cache contents, prompts and secrets or corrupt memory toward code execution."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-822",
                  "description": "Untrusted Pointer Dereference",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T23:19:57.849Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Issue #4441",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake/issues/4441"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake/commit/a2933849417259e562fc9cbad63c618d464dfb2d"
            },
            {
              "name": "Mooncake v0.3.13 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake/releases/tag/v0.3.13"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake/blob/6041a609a8c3af35e778f70db344f145c2914980/mooncake-transfer-engine/src/transport/tcp_transport/tcp_transport.cpp#L209"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake"
            },
            {
              "name": "VulnCheck Advisory: Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/mooncake-transfer-engine-before-0.3.13-unauthenticated-arbitrary-memory-read-write-via-tcp-transport"
            }
          ],
          "title": "Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-103764",
        "datePublished": "2026-10-01T23:19:57.849Z",
        "dateReserved": "2026-10-01T10:39:47.845Z",
        "dateUpdated": "2026-10-01T23:19:57.849Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-103761 (GCVE-0-2026-103761)

    Vulnerability from cvelistv5 – Published: 2026-10-01 22:53 – Updated: 2026-10-01 22:53
    VLAI
    Title
    Mooncake transfer engine through 0.3.13.post1 Memory Exhaustion via Unbounded Notify Queue
    Summary
    Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly send notify frames up to 1 MB to the handshake RPC port, filling the uncapped notifys vector until the out-of-memory killer terminates the engine.
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    Impacted products
    Vendor Product Version
    kvcache-ai Mooncake Affected: 0 , ≤ 0.3.13.post1 (custom)
    Create a notification for this product.
    Date Public
    2026-10-01 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:pypi/mooncake-transfer-engine",
              "product": "Mooncake",
              "vendor": "kvcache-ai",
              "versions": [
                {
                  "lessThanOrEqual": "0.3.13.post1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Mingkai Yu"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Jiajia Liu"
            }
          ],
          "datePublic": "2026-10-01T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly send notify frames up to 1 MB to the handshake RPC port, filling the uncapped notifys vector until the out-of-memory killer terminates the engine."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T22:53:06.016Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Issue #4445",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake/issues/4445"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake/blob/719735896c86b56fabec6cf3e825fb2ea640597a/mooncake-transfer-engine/src/transfer_metadata.cpp#L285-L296"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake"
            },
            {
              "name": "VulnCheck Advisory: Mooncake transfer engine through 0.3.13.post1 Memory Exhaustion via Unbounded Notify Queue",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/mooncake-transfer-engine-through-0.3.13-post1-memory-exhaustion-via-unbounded-notify-queue"
            }
          ],
          "title": "Mooncake transfer engine through 0.3.13.post1 Memory Exhaustion via Unbounded Notify Queue",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-103761",
        "datePublished": "2026-10-01T22:53:06.016Z",
        "dateReserved": "2026-10-01T10:39:47.845Z",
        "dateUpdated": "2026-10-01T22:53:06.016Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-103760 (GCVE-0-2026-103760)

    Vulnerability from cvelistv5 – Published: 2026-10-01 22:53 – Updated: 2026-10-01 22:53
    VLAI
    Title
    Mooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Handshake Daemon Response Write
    Summary
    Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers can send a Metadata request to the handshake RPC port and stall SocketHandShakePlugin's single listener thread in writeFully(), breaking all subsequent handshakes, metadata fetches, notify and probe requests.
    CWE
    • CWE-400 - Uncontrolled Resource Consumption
    Impacted products
    Vendor Product Version
    kvcache-ai Mooncake Affected: 0 , ≤ 0.3.13.post1 (custom)
    Create a notification for this product.
    Date Public
    2026-10-01 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:pypi/mooncake-transfer-engine",
              "product": "Mooncake",
              "vendor": "kvcache-ai",
              "versions": [
                {
                  "lessThanOrEqual": "0.3.13.post1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Mingkai Yu"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Jiajia Liu"
            }
          ],
          "datePublic": "2026-10-01T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers can send a Metadata request to the handshake RPC port and stall SocketHandShakePlugin\u0027s single listener thread in writeFully(), breaking all subsequent handshakes, metadata fetches, notify and probe requests."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 8.2,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": "Uncontrolled Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T22:53:05.201Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Issue #4443",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake/issues/4443"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake/blob/719735896c86b56fabec6cf3e825fb2ea640597a/mooncake-transfer-engine/src/transfer_metadata_plugin.cpp#L730-L803"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake"
            },
            {
              "name": "VulnCheck Advisory: Mooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Handshake Daemon Response Write",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/mooncake-transfer-engine-through-0.3.13-post1-denial-of-service-via-p2p-handshake-daemon-response-write"
            }
          ],
          "title": "Mooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Handshake Daemon Response Write",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-103760",
        "datePublished": "2026-10-01T22:53:05.201Z",
        "dateReserved": "2026-10-01T10:39:47.845Z",
        "dateUpdated": "2026-10-01T22:53:05.201Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-96764 (GCVE-0-2026-96764)

    Vulnerability from cvelistv5 – Published: 2026-09-24 00:15 – Updated: 2026-09-24 14:33
    VLAI
    Title
    kvcache-ai mooncake Regular Expression GetReplicaListByRegex allocation of resources
    Summary
    A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1. Impacted is the function MasterService::GetReplicaListByRegex of the component Regular Expression Handler. Executing a manipulation can lead to allocation of resources. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-24 14:33 UTC
    CWE
    References
    URL Tags
    https://vuldb.com/vuln/409019 vdb-entrytechnical-description
    https://vuldb.com/vuln/409019/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-96764 third-party-advisory
    https://vuldb.com/submit/904607 third-party-advisory
    https://gist.github.com/yyymk/4699cc95ab9a559ee15… exploit
    Impacted products
    Vendor Product Version
    kvcache-ai mooncake Affected: 0.3.0
    Affected: 0.3.1
    Affected: 0.3.2
    Affected: 0.3.3
    Affected: 0.3.4
    Affected: 0.3.5
    Affected: 0.3.6
    Affected: 0.3.7
    Affected: 0.3.8
    Affected: 0.3.9
    Affected: 0.3.10
    Affected: 0.3.11
    Affected: 0.3.12
    Affected: 0.3.14-rc1
        cpe:2.3:a:kvcache-ai:mooncake:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-96764",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-24T14:33:17.401895Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-24T14:33:28.453Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:kvcache-ai:mooncake:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Regular Expression Handler"
              ],
              "product": "mooncake",
              "vendor": "kvcache-ai",
              "versions": [
                {
                  "status": "affected",
                  "version": "0.3.0"
                },
                {
                  "status": "affected",
                  "version": "0.3.1"
                },
                {
                  "status": "affected",
                  "version": "0.3.2"
                },
                {
                  "status": "affected",
                  "version": "0.3.3"
                },
                {
                  "status": "affected",
                  "version": "0.3.4"
                },
                {
                  "status": "affected",
                  "version": "0.3.5"
                },
                {
                  "status": "affected",
                  "version": "0.3.6"
                },
                {
                  "status": "affected",
                  "version": "0.3.7"
                },
                {
                  "status": "affected",
                  "version": "0.3.8"
                },
                {
                  "status": "affected",
                  "version": "0.3.9"
                },
                {
                  "status": "affected",
                  "version": "0.3.10"
                },
                {
                  "status": "affected",
                  "version": "0.3.11"
                },
                {
                  "status": "affected",
                  "version": "0.3.12"
                },
                {
                  "status": "affected",
                  "version": "0.3.14-rc1"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "YYYMK (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1. Impacted is the function MasterService::GetReplicaListByRegex of the component Regular Expression Handler. Executing a manipulation can lead to allocation of resources. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 4,
                "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "Allocation of Resources",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": "Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-24T00:15:12.968Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-409019 | kvcache-ai mooncake Regular Expression GetReplicaListByRegex allocation of resources",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/409019"
            },
            {
              "name": "VDB-409019 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/409019/cti"
            },
            {
              "name": "CVE-2026-96764 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-96764"
            },
            {
              "name": "Submit #904607 | kvcache-ai mooncake \u003e= 0.3.4, \u003c= 0.3.12 Denial of Service",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/904607"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://gist.github.com/yyymk/4699cc95ab9a559ee15a0fb798bd6c5d"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-23T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-23T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-23T18:06:38.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "kvcache-ai mooncake Regular Expression GetReplicaListByRegex allocation of resources",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-96764",
        "datePublished": "2026-09-24T00:15:12.968Z",
        "dateReserved": "2026-09-23T16:01:24.847Z",
        "dateUpdated": "2026-09-24T14:33:28.453Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-96763 (GCVE-0-2026-96763)

    Vulnerability from cvelistv5 – Published: 2026-09-24 00:00 – Updated: 2026-09-29 02:41
    VLAI
    Title
    kvcache-ai mooncake MountSegment Request Processing segment.cpp access control
    Summary
    A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc1. This issue affects the function ScopedSegmentAccess::MountSegment of the file segment.cpp of the component MountSegment Request Processing. Performing a manipulation results in improper access controls. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 02:41 UTC
    CWE
    • CWE-284 - Improper Access Controls
    • CWE-266 - Incorrect Privilege Assignment
    References
    URL Tags
    https://vuldb.com/vuln/409018 vdb-entrytechnical-description
    https://vuldb.com/vuln/409018/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-96763 third-party-advisory
    https://vuldb.com/submit/904605 third-party-advisory
    https://gist.github.com/yyymk/fea24846dc31042cb47… exploit
    Impacted products
    Vendor Product Version
    kvcache-ai mooncake Affected: 0.3.0
    Affected: 0.3.1
    Affected: 0.3.2
    Affected: 0.3.3
    Affected: 0.3.4
    Affected: 0.3.5
    Affected: 0.3.6
    Affected: 0.3.7
    Affected: 0.3.8
    Affected: 0.3.9
    Affected: 0.3.10
    Affected: 0.3.11
    Affected: 0.3.12
    Affected: 0.3.13.post1
    Affected: 0.3.14-rc1
        cpe:2.3:a:kvcache-ai:mooncake:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-96763",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T02:41:13.416455Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T02:41:22.511Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:kvcache-ai:mooncake:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "MountSegment Request Processing"
              ],
              "product": "mooncake",
              "vendor": "kvcache-ai",
              "versions": [
                {
                  "status": "affected",
                  "version": "0.3.0"
                },
                {
                  "status": "affected",
                  "version": "0.3.1"
                },
                {
                  "status": "affected",
                  "version": "0.3.2"
                },
                {
                  "status": "affected",
                  "version": "0.3.3"
                },
                {
                  "status": "affected",
                  "version": "0.3.4"
                },
                {
                  "status": "affected",
                  "version": "0.3.5"
                },
                {
                  "status": "affected",
                  "version": "0.3.6"
                },
                {
                  "status": "affected",
                  "version": "0.3.7"
                },
                {
                  "status": "affected",
                  "version": "0.3.8"
                },
                {
                  "status": "affected",
                  "version": "0.3.9"
                },
                {
                  "status": "affected",
                  "version": "0.3.10"
                },
                {
                  "status": "affected",
                  "version": "0.3.11"
                },
                {
                  "status": "affected",
                  "version": "0.3.12"
                },
                {
                  "status": "affected",
                  "version": "0.3.13.post1"
                },
                {
                  "status": "affected",
                  "version": "0.3.14-rc1"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "YYYMK (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc1. This issue affects the function ScopedSegmentAccess::MountSegment of the file segment.cpp of the component MountSegment Request Processing. Performing a manipulation results in improper access controls. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 6.4,
                "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "Improper Access Controls",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-266",
                  "description": "Incorrect Privilege Assignment",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-24T00:00:16.519Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-409018 | kvcache-ai mooncake MountSegment Request Processing segment.cpp access control",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/409018"
            },
            {
              "name": "VDB-409018 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/409018/cti"
            },
            {
              "name": "CVE-2026-96763 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-96763"
            },
            {
              "name": "Submit #904605 | kvcache-ai mooncake mooncake-transfer-engine==0.3.11.post1 Access Control",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/904605"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://gist.github.com/yyymk/fea24846dc31042cb472d7bd496a8438"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-23T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-23T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-23T18:06:34.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "kvcache-ai mooncake MountSegment Request Processing segment.cpp access control",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-96763",
        "datePublished": "2026-09-24T00:00:16.519Z",
        "dateReserved": "2026-09-23T16:01:21.340Z",
        "dateUpdated": "2026-09-29T02:41:22.511Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-96762 (GCVE-0-2026-96762)

    Vulnerability from cvelistv5 – Published: 2026-09-23 23:45 – Updated: 2026-09-24 13:18
    VLAI
    Title
    kvcache-ai mooncake RPC Path UnmountSegment authorization
    Summary
    A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegment of the component RPC Path Handler. This manipulation of the argument client_id/segment_id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-24 13:17 UTC
    CWE
    References
    URL Tags
    https://vuldb.com/vuln/409016 vdb-entrytechnical-description
    https://vuldb.com/vuln/409016/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-96762 third-party-advisory
    https://vuldb.com/submit/904600 third-party-advisory
    https://gist.github.com/yyymk/76d099537af0e661dd0… exploit
    Impacted products
    Vendor Product Version
    kvcache-ai mooncake Affected: 0.3.0
    Affected: 0.3.1
    Affected: 0.3.2
    Affected: 0.3.3
    Affected: 0.3.4
    Affected: 0.3.5
    Affected: 0.3.6
    Affected: 0.3.7
    Affected: 0.3.8
    Affected: 0.3.9
    Affected: 0.3.10
    Affected: 0.3.11
    Affected: 0.3.12
    Affected: 0.3.13.post1
        cpe:2.3:a:kvcache-ai:mooncake:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-96762",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-24T13:17:42.616673Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-24T13:18:16.683Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:kvcache-ai:mooncake:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "RPC Path Handler"
              ],
              "product": "mooncake",
              "vendor": "kvcache-ai",
              "versions": [
                {
                  "status": "affected",
                  "version": "0.3.0"
                },
                {
                  "status": "affected",
                  "version": "0.3.1"
                },
                {
                  "status": "affected",
                  "version": "0.3.2"
                },
                {
                  "status": "affected",
                  "version": "0.3.3"
                },
                {
                  "status": "affected",
                  "version": "0.3.4"
                },
                {
                  "status": "affected",
                  "version": "0.3.5"
                },
                {
                  "status": "affected",
                  "version": "0.3.6"
                },
                {
                  "status": "affected",
                  "version": "0.3.7"
                },
                {
                  "status": "affected",
                  "version": "0.3.8"
                },
                {
                  "status": "affected",
                  "version": "0.3.9"
                },
                {
                  "status": "affected",
                  "version": "0.3.10"
                },
                {
                  "status": "affected",
                  "version": "0.3.11"
                },
                {
                  "status": "affected",
                  "version": "0.3.12"
                },
                {
                  "status": "affected",
                  "version": "0.3.13.post1"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "YYYMK (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegment of the component RPC Path Handler. This manipulation of the argument client_id/segment_id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 7.5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "Authorization Bypass",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-285",
                  "description": "Improper Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-23T23:45:14.276Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-409016 | kvcache-ai mooncake RPC Path UnmountSegment authorization",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/409016"
            },
            {
              "name": "VDB-409016 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/409016/cti"
            },
            {
              "name": "CVE-2026-96762 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-96762"
            },
            {
              "name": "Submit #904600 | kvcache-ai Mooncake \u003e= 0.3.4, \u003c= 0.3.12 Authorization Bypass",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/904600"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://gist.github.com/yyymk/76d099537af0e661dd01eacc82b9a7ea"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-23T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-23T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-23T18:06:31.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "kvcache-ai mooncake RPC Path UnmountSegment authorization",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-96762",
        "datePublished": "2026-09-23T23:45:14.276Z",
        "dateReserved": "2026-09-23T16:01:17.341Z",
        "dateUpdated": "2026-09-24T13:18:16.683Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }