Impact
Mooncake transfer engine versions prior to 0.3.13 contain a flaw in ServerSession::readHeader where an untrusted pointer is dereferenced. This allows an unauthenticated attacker to send a crafted SessionHeader with any address and size over the TCP transport port. The attacker can then use READ or WRITE opcodes to read or overwrite arbitrary process memory, potentially exposing cache contents, prompts, secrets, or enabling code execution.
Affected Systems
The vulnerability affects the Mooncake product from kvcache-ai. Any release before 0.3.13 is vulnerable; the issue is fixed in version 0.3.13 and later.
Risk and Exploitability
The CVSS score of 9.3 reflects a high severity due to complete loss of confidentiality, integrity and availability. EPSS data is not available, so the exact likelihood of exploitation is unknown, but the flaw is network‑reachable and unauthenticated, making it highly exploitable in a connected environment. The vulnerability is not yet listed in the CISA KEV catalog, but its impact warrants immediate attention and remediation over the TCP transport port.
OpenCVE Enrichment