PT-2026-104055 · Unknown · Mooncake Transfer Engine
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Mooncake transfer engine versions prior to 0.3.14
Description
A denial of service issue allows unauthenticated remote attackers to block the handshake daemon by failing to read replies. By sending a Metadata request to the handshake RPC port, an attacker can stall the single listener thread of the
SocketHandShakePlugin within the writeFully() function. This action disrupts all subsequent handshakes, metadata fetches, notify, and probe requests.Recommendations
Update Mooncake transfer engine to version 0.3.14 or later.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mooncake Transfer Engine