Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attackers can connect to the handshake port listening on all interfaces and send an eight-byte frame to terminate the hosting process, such as an SGLang inference server.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104433.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104433.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"205696808118481514438618394071282174364",
"252703981900679507375191080287019195791",
"123290894177174466210025112847491926467"
],
"threshold": 0.9
},
"id": "CVE-2026-104433-1074f921",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/kvcache-ai/mooncake/commit/c142b40590259360196d8e504b2193382529e7b4",
"target": {
"file": "mooncake-transfer-engine/include/common.h"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"208626284151766976122132100156730131416",
"53443675378967298753025647378223473023",
"220466968840857572433313147237698444549",
"153616159007328621715590750309945105847"
],
"threshold": 0.9
},
"id": "CVE-2026-104433-34e36257",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/kvcache-ai/mooncake/commit/c142b40590259360196d8e504b2193382529e7b4",
"target": {
"file": "mooncake-transfer-engine/src/transfer_engine_impl.cpp"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "41662267458183126134998144721204259552",
"length": 946
},
"id": "CVE-2026-104433-52bff35e",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/kvcache-ai/mooncake/commit/c142b40590259360196d8e504b2193382529e7b4",
"target": {
"file": "mooncake-transfer-engine/include/common.h",
"function": "readString"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"289821992277650586352305565484500038508",
"208236549094587803094933737729992914072",
"185180219706740571168939907307478940434",
"148268215849480185960938913399340285723",
"289821992277650586352305565484500038508",
"208236549094587803094933737729992914072",
"185180219706740571168939907307478940434",
"148268215849480185960938913399340285723",
"289821992277650586352305565484500038508",
"208236549094587803094933737729992914072",
"185180219706740571168939907307478940434",
"148268215849480185960938913399340285723",
"289821992277650586352305565484500038508",
"208236549094587803094933737729992914072",
"185180219706740571168939907307478940434",
"148268215849480185960938913399340285723"
],
"threshold": 0.9
},
"id": "CVE-2026-104433-58a86c30",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/kvcache-ai/mooncake/commit/c142b40590259360196d8e504b2193382529e7b4",
"target": {
"file": "mooncake-transfer-engine/src/transfer_metadata_plugin.cpp"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "92408173803971510115170564095493341524",
"length": 225
},
"id": "CVE-2026-104433-7344edfa",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/kvcache-ai/mooncake/commit/c142b40590259360196d8e504b2193382529e7b4",
"target": {
"file": "mooncake-transfer-engine/src/transfer_engine_impl.cpp",
"function": "TransferEngineImpl::sendNotifyByID"
}
}
]
"2026-10-04T07:03:19Z"