Impact
The vulnerability is a missing authentication flaw in Mooncake’s HTTP metadata server /metadata handler that permits any network caller to read, modify, or delete transfer engine metadata keys. By overwriting keys such as tcp_data_port or recreating rpc_meta entries, an attacker can redirect KV cache traffic to attacker‑controlled listeners or exhaust server memory through repeated writes. This flaw is a Credential‑or‑Authentication‑Related weakness (CWE‑306) that can lead to unauthorized configuration changes and potential denial‑of‑service attacks.
Affected Systems
The problem affects Mooncake applications from kvcache‑ai released through version 0.3.13.post1. Users running that version or earlier are susceptible; newer releases should address the flaw but consult the vendor’s changelog to confirm the fix.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, signaling high severity. Though EPSS data is not available and it is not listed in CISA’s KEV catalog, the attack vector is a straightforward network‑based HTTP request to /metadata that does not require authentication. An unauthenticated attacker could exploit the flaw immediately if the server is reachable, suggesting a non‑negligible risk of exploitation and a strong business impact if left unmitigated.
OpenCVE Enrichment