{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/transfer-engine--0.3.12/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mooncake:transfer_engine:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-103764"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["transfer engine (\u003c 0.3.13)","transfer engine (\u003c 0.3.12)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","rce","memory-corruption"],"_cs_type":"advisory","_cs_vendors":["Mooncake"],"content_html":"\u003cp\u003eThe Mooncake transfer engine prior to version 0.3.13 is susceptible to an untrusted pointer dereference vulnerability residing in the ServerSession::readHeader function. This flaw allows unauthenticated remote attackers to interact with the service over its TCP transport data port. By crafting a malicious SessionHeader containing arbitrary address and size fields, an attacker can issue READ or WRITE opcodes. These operations enable the unauthorized disclosure of sensitive internal information, such as KV cache contents, prompts, and system secrets. Furthermore, the ability to perform arbitrary memory writes allows for potential memory corruption, which may be leveraged to achieve remote code execution on the host running the transfer engine. Given the severity of this vulnerability and the lack of authentication requirements, defenders should prioritize patching to version 0.3.13 or later.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-103764 results in full compromise of the affected process memory. Impact includes the theft of sensitive proprietary data, such as cached prompts and secrets, and potential full system compromise via arbitrary code execution. This impacts any environment deploying Mooncake transfer engine versions prior to 0.3.13 exposed to untrusted network segments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Mooncake transfer engine to version 0.3.13 or later immediately to address the underlying pointer dereference flaw.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the Mooncake TCP transport data port to trusted IP addresses only, reducing the attack surface until patches can be applied.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic for anomalous sequences targeting the transfer engine port, specifically looking for header anomalies or large-scale data transfer patterns indicative of memory dumping.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-03T00:49:42Z","date_published":"2026-10-02T00:19:35Z","id":"https://feed.craftedsignal.io/briefs/2026-10-mooncake-memory-corruption/","summary":"An untrusted pointer dereference vulnerability (CVE-2026-103764) in the Mooncake transfer engine allows unauthenticated attackers to perform arbitrary memory reads and writes, potentially leading to remote code execution.","title":"Arbitrary Memory Access Vulnerability in Mooncake Transfer Engine","url":"https://feed.craftedsignal.io/briefs/2026-10-mooncake-memory-corruption/"}],"language":"en","title":"CraftedSignal Threat Feed - Transfer Engine (\u003c 0.3.12)","version":"https://jsonfeed.org/version/1.1"}