Known Vulnerabilities for Mooncake by Kvcache-ai
Listed below are 10 of the newest known vulnerabilities associated with "Mooncake" by "Kvcache-ai".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-103765 json | Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler t... | Not Provided | 2026-10-02 | 2026-10-01 |
| CVE-2026-103764 json | Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows una... | Not Provided | 2026-10-02 | 2026-10-01 |
| CVE-2026-103761 json | Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNoti... | Not Provided | 2026-10-01 | 2026-10-01 |
| CVE-2026-103760 json | Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote a... | Not Provided | 2026-10-01 | 2026-10-01 |
| CVE-2026-102634 json | SGLang through 0.5.20 in prefill/decode disaggregation mode fails to validate duplicate bootstrap_room fields in /generate re... | Not Provided | 2026-09-29 | 2026-09-29 |
| CVE-2026-96764 json | A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1. Impacted is the function MasterService::GetRep... | Not Provided | 2026-09-24 | 2026-09-24 |
| CVE-2026-96763 json | A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc1. This issue affects the funct... | Not Provided | 2026-09-24 | 2026-09-29 |
| CVE-2026-96762 json | A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegment of ... | Not Provided | 2026-09-24 | 2026-09-24 |
| CVE-2026-94627 json | vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests s... | Not Provided | 2026-09-21 | 2026-09-22 |
| CVE-2026-93688 json | SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_roo... | Not Provided | 2026-09-18 | 2026-09-21 |