Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-104433 is an out-of-bounds read vulnerability in the Mooncake transfer engine before version 0.3.12. The flaw exists in the readString function in include/common.h and can be triggered by unauthenticated attackers sending a zero-length handshake frame. Exploitation allows attackers to crash the service by sending an eight-byte frame to the handshake port, terminating the hosting process such as an SGLang inference server. Join the discussion | CVE Database V5 | 10/02/2026, 23:28:44 UTC Added: 10/02/2026, 23:31:35 UTC |
Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or WRITE opcodes to disclose KV cache contents, prompts and secrets or corrupt memory toward code execution. Join the discussion | CVE Database V5 | 10/01/2026, 23:19:57 UTC Added: 10/01/2026, 23:31:48 UTC |
0 Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly send notify frames up to 1 MB to the handshake RPC port, filling the uncapped notifys vector until the out-of-memory killer terminates the engine. Join the discussion | CVE Database V5 | 10/01/2026, 22:53:06 UTC Added: 10/01/2026, 23:02:07 UTC |
Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers can send a Metadata request to the handshake RPC port and stall SocketHandShakePlugin's single listener thread in writeFully(), breaking all subsequent handshakes, metadata fetches, notify and probe requests. Join the discussion | CVE Database V5 | 10/01/2026, 22:53:05 UTC Added: 10/01/2026, 23:02:07 UTC |
A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1. Impacted is the function MasterService::GetReplicaListByRegex of the component Regular Expression Handler. Executing a manipulation can lead to allocation of resources. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 09/24/2026, 00:15:12 UTC Added: 09/24/2026, 00:33:29 UTC |
A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc1. This issue affects the function ScopedSegmentAccess::MountSegment of the file segment.cpp of the component MountSegment Request Processing. Performing a manipulation results in improper access controls. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 09/24/2026, 00:00:16 UTC Added: 09/24/2026, 00:33:29 UTC |
Showing 1 to 6 of 6 results