---
id: CVE-2026-104433
title: >-
  Mooncake transfer engine before 0.3.12 contains an out-of-bounds read
  vulnerability in the readString function of include/common.h that allows
  unauthenticated attackers to crash the service by sending a zero-length
  handshake frame
summary: >-
  Mooncake transfer engine before 0.3.12 contains an out-of-bounds read
  vulnerability in the readString function of include/common.h that allows
  unauthenticated attackers to crash the service by sending a zero-length
  handshake frame. Attac…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-125
vendor: kvcache-ai
product: Mooncake
affected:
  - Mooncake < 0.3.12
published: '2026-10-03'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T00:16:35.253'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104433'
references:
  - url: 'https://github.com/kvcache-ai/Mooncake'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/kvcache-ai/Mooncake/commit/c142b40590259360196d8e504b2193382529e7b4
    label: disclosure@vulncheck.com
  - url: 'https://github.com/kvcache-ai/Mooncake/issues/4452'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/mooncake-before-0.3.12-out-of-bounds-read-via-p2p-handshake-readstring
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T23:34:57.408Z'
---

## Overview

Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attackers can connect to the handshake port listening on all interfaces and send an eight-byte frame to terminate the hosting process, such as an SGLang inference server.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
