๐Ÿ” CVE Alert

CVE-2026-96764

MEDIUM 4.3

kvcache-ai mooncake Regular Expression GetReplicaListByRegex allocation of resources

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1. Impacted is the function MasterService::GetReplicaListByRegex of the component Regular Expression Handler. Executing a manipulation can lead to allocation of resources. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CWE CWE-770 CWE-400
Vendor kvcache-ai
Product mooncake
Published Sep 24, 2026
Stay Ahead of the Next One

Get instant alerts for kvcache-ai mooncake

Be the first to know when new medium vulnerabilities affecting kvcache-ai mooncake are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

kvcache-ai / mooncake
0.3.0 0.3.1 0.3.2 0.3.3 0.3.4 0.3.5 0.3.6 0.3.7 0.3.8 0.3.9 0.3.10 0.3.11 0.3.12 0.3.14-rc1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/409019 vuldb.com: https://vuldb.com/vuln/409019/cti vuldb.com: https://vuldb.com/cve/CVE-2026-96764 vuldb.com: https://vuldb.com/submit/904607 gist.github.com: https://gist.github.com/yyymk/4699cc95ab9a559ee15a0fb798bd6c5d

Credits

๐Ÿ” YYYMK (VulDB User) VulDB CNA Team