Description
Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison segment descriptors such as tcp_data_port or re-create rpc_meta entries to redirect KV cache transfers to attacker-controlled listeners, or exhaust server memory.
Published: 2026-10-01
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: unauthenticated metadata manipulation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a missing authentication flaw in Mooncake’s HTTP metadata server /metadata handler that permits any network caller to read, modify, or delete transfer engine metadata keys. By overwriting keys such as tcp_data_port or recreating rpc_meta entries, an attacker can redirect KV cache traffic to attacker‑controlled listeners or exhaust server memory through repeated writes. This flaw is a Credential‑or‑Authentication‑Related weakness (CWE‑306) that can lead to unauthorized configuration changes and potential denial‑of‑service attacks.

Affected Systems

The problem affects Mooncake applications from kvcache‑ai released through version 0.3.13.post1. Users running that version or earlier are susceptible; newer releases should address the flaw but consult the vendor’s changelog to confirm the fix.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.8, signaling high severity. Though EPSS data is not available and it is not listed in CISA’s KEV catalog, the attack vector is a straightforward network‑based HTTP request to /metadata that does not require authentication. An unauthenticated attacker could exploit the flaw immediately if the server is reachable, suggesting a non‑negligible risk of exploitation and a strong business impact if left unmitigated.

Generated by OpenCVE AI on October 2, 2026 at 00:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Mooncake to a release following 0.3.13.post1 that includes the authentication fix
  • Restrict network exposure of the /metadata endpoint by applying firewall rules or network segmentation so that only trusted systems can reach it
  • Continuously monitor logs and network traffic for suspicious metadata key modifications or repeated overwrite attempts
  • Consider disabling the HTTP metadata server if the functionality is not required for the workload

Generated by OpenCVE AI on October 2, 2026 at 00:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Kvcache-ai
Kvcache-ai mooncake
Vendors & Products Kvcache-ai
Kvcache-ai mooncake

Thu, 01 Oct 2026 23:30:00 +0000

Type Values Removed Values Added
Description Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison segment descriptors such as tcp_data_port or re-create rpc_meta entries to redirect KV cache transfers to attacker-controlled listeners, or exhaust server memory.
Title Mooncake through 0.3.13.post1 Missing Authentication in HTTP Metadata Server
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Kvcache-ai Mooncake
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T23:19:58.492Z

Reserved: 2026-10-01T10:39:47.845Z

Link: CVE-2026-103765

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T00:16:59.663

Modified: 2026-10-02T00:16:59.663

Link: CVE-2026-103765

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T00:30:16Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function