Impact
Mooncake transfer engine before version 0.3.12 contains an out‑of‑bounds read in the readString routine within include/common.h. An unauthenticated attacker can send a specially crafted, zero‑length handshake frame that causes the engine to read eight bytes beyond the buffer, leading to a crash and termination of the hosting process, such as an SGLang inference server. The flaw does not provide code execution or information disclosure, but it does permit a denial‑of‑service attack that can bring dependent services offline.
Affected Systems
The affected product is the Mooncake transfer engine distributed by kvcache-ai. All releases prior to 0.3.12 are vulnerable. Systems that expose the P2P handshake port, including SGLang inference servers that bind to all network interfaces, are impacted.
Risk and Exploitability
The CVSS score of 8.7 places this vulnerability in the high‑severity range. The EPSS score is not available and it is not listed in CISA’s KEV catalog, indicating limited known exploitation. Attackers can exploit it remotely through the handshake port, requiring no authentication or special privileges. The absence of exploitation data suggests uncertainty about real‑world use, but the high availability impact warrants prompt attention.
OpenCVE Enrichment