CVE-2026-103764 | kvcache-ai Mooncake up to 0.3.12 transfer engine readHeader addr/size null pointer dereference
A vulnerability was found in kvcache-ai Mooncake up to 0.3.12. It has been rated as critical. Affected by this issue is the function ServerSession::readHeader of the component transfer engine. The manipulation of the argument addr/size leads to null pointer dereference.
This vulnerability is listed as CVE-2026-103764. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.VulDB Recent EntriesRead More