kvcache-ai has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 5.4 (medium).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.4
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Worst active — by depth score
CVE-2026-96762High· 7.3A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post140CVE-2026-96763Medium· 5.4A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc130CVE-2026-96764Medium· 4.3A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc124
kvcache-ai vulnerabilities
CVEs affecting kvcache-ai, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-96763Medium· 5.4A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc1
A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc1. This issue affects the function ScopedSegmentAccess::MountSegment of the file segment.cpp of the component MountSegment Request Processing. …
CVE-2026-96764Medium· 4.3A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1
A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1. Impacted is the function MasterService::GetReplicaListByRegex of the component Regular Expression Handler. Executing a manipulation can lead to allocation of …
CVE-2026-96762High· 7.3A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1
A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegment of the component RPC Path Handler. This manipulation of the argument client_id/segment_id causes authorization bypa…