---
id: CVE-2026-96764
title: A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1
summary: >-
  A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1.
  Impacted is the function MasterService::GetReplicaListByRegex of the component
  Regular Expression Handler. Executing a manipulation can lead to allocation of
  …
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-400
  - CWE-770
vendor: kvcache-ai
product: mooncake
affected:
  - mooncake 0.3.0
  - mooncake 0.3.1
  - mooncake 0.3.2
  - mooncake 0.3.3
  - mooncake 0.3.4
  - mooncake 0.3.5
  - mooncake 0.3.6
  - mooncake 0.3.7
  - mooncake 0.3.8
  - mooncake 0.3.9
  - mooncake 0.3.10
  - mooncake 0.3.11
  - mooncake 0.3.12
  - mooncake 0.3.14-rc1
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T15:18:00.490'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96764'
references:
  - url: 'https://gist.github.com/yyymk/4699cc95ab9a559ee15a0fb798bd6c5d'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-96764'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/904607'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/409019'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/409019/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-24T14:33:17.401895Z'
ingestedAt: '2026-09-24T00:35:28.614Z'
epss: 0.00271
epssPercentile: 0.17154
---

## Overview

A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1. Impacted is the function MasterService::GetReplicaListByRegex of the component Regular Expression Handler. Executing a manipulation can lead to allocation of resources. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
