PT-2026-104055 · Unknown · Mooncake Transfer Engine

·

CVE-2026-103760

·

Published

2026-10-01

·

Updated

2026-10-02

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Mooncake transfer engine versions prior to 0.3.14
Description A denial of service issue allows unauthenticated remote attackers to block the handshake daemon by failing to read replies. By sending a Metadata request to the handshake RPC port, an attacker can stall the single listener thread of the SocketHandShakePlugin within the writeFully() function. This action disrupts all subsequent handshakes, metadata fetches, notify, and probe requests.
Recommendations Update Mooncake transfer engine to version 0.3.14 or later.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103760

Affected Products

Mooncake Transfer Engine