OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-103765

CRITICAL · CVSS 9.4 EPSS 0.50% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability in Mooncake allows unauthenticated attackers to access and manipulate transfer engine metadata through the HTTP metadata server, potentially leading to unauthorized reading, overwriting, or deletion of critical metadata keys. This could enable attackers to redirect KV cache transfers to malicious listeners or exhaust server memory, posing a severe risk to system integrity and availability. Organizations using Mooncake, particularly those handling sensitive data or relying on metadata for operations, should prioritize immediate remediation efforts.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-103765
Severity
CRITICAL
CVSS
9.4
EPSS
0.50%

Original NVD Description

Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison segment descriptors such as tcp_data_port or re-create rpc_meta entries to redirect KV cache transfers to attacker-controlled listeners, or exhaust server memory.