high · CVSS v3 7.5 · CVSS v4 8.7
CVE-2026-104433
Mooncake Transfer Engine versions prior to 0.3.12 contain an out‑of‑bounds read in the readString function that can be triggered by an unaut
Overview
Mooncake Transfer Engine versions prior to 0.3.12 contain an out‑of‑bounds read in the readString function that can be triggered by an unauthenticated attacker sending a zero‑length handshake frame. The flaw causes the service to crash, potentially disrupting SGLang inference servers or other applications using the engine. It is a high‑severity vulnerability that can lead to denial of service.
Description
Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attackers can connect to the handshake port listening on all interfaces and send an eight-byte frame to terminate the hosting process, such as an SGLang inference server.
Impact
The vulnerability allows attackers to crash the target service, resulting in a denial of service. This directly impacts availability for systems relying on the Mooncake engine, such as AI inference workloads. The flaw does not expose data or allow remote code execution, but it can be used to disrupt operations.
Remediation
Upgrade Mooncake Transfer Engine to version 0.3.12 or later, which removes the out‑of‑bounds read. If an upgrade is not immediately possible, restrict inbound traffic to the handshake port using firewall rules or network segmentation to limit unauthenticated access. Monitor logs for abnormal handshake frames and apply temporary service restarts to mitigate ongoing impact.
Risk context
The CVSS v3 score of 7.5 and v4 score of 8.7 classify this as a high‑severity denial of service vulnerability. While no EPSS data is available, the lack of authentication and the ability to crash the service make it urgent for defenders to apply the patch or mitigate exposure.
Affected products
- Mooncake Transfer Engine
- SGLang inference server
Scores
- Severity
- high
- CVSS v2
- 7.8
- CVSS v3
- 7.5
- CVSS v4
- 8.7
- EPSS
- —