CVE-2026-104433
Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allo
CVSS
7.5
High
EPSS
0.4%
p28
KEV
—
Exploit Today
8
0-100
Published: Oct 3, 2026 · Last modified: Oct 3, 2026 · CWE-125
0.4%EPSS · 30 days0.4%
2026-10-032026-10-04
Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attackers can connect to the handshake port listening on all interfaces and send an eight-byte frame to terminate the hosting process, such as an SGLang inference server.
- github.comhttps://github.com/kvcache-ai/Mooncake
- github.comhttps://github.com/kvcache-ai/Mooncake/commit/c142b40590259360196d8e504b2193382529e7b4
- github.comhttps://github.com/kvcache-ai/Mooncake/issues/4452
- www.vulncheck.comhttps://www.vulncheck.com/advisories/mooncake-before-0.3.12-out-of-bounds-read-via-p2p-handshake-readstring
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-1051642.7 LOW—
——0A flaw has been found in NASA cFS up to 7.0.1. This issue affects the function CFE_FS_ParseInputFileNameEx of the file cfe/modules/fs/fsw/src/cfe_fs_api.c. This manipulation causes out-of-bounds read. Remote exploitation of the attack is possible. The pull request to fix this issue awaits acceptance.8hCVE-2026-798967.5 HIG23.6%
——7Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service interruption.3dCVE-2026-1036785.4 MED9.4%
——3A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory occurs. This flaw can cause the application to crash, leading to a Denial of Service (DoS), or leak sensitive memory contents into extracted output files.4dCVE-2026-1036415.5 MED3.1%
——1A flaw was found in GEGL. The Radiance HDR loader reads past the end of a memory-mapped image when an uncompressed scanline is shorter than the width declared in the file header. Opening a crafted HDR file crashes the application that uses the loader.3dCVE-2026-475927.8 HIG2.0%
——1NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.3dCVE-2026-475457.8 HIG2.6%
——1NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.4d