Description
Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers can send a Metadata request to the handshake RPC port and stall SocketHandShakePlugin's single listener thread in writeFully(), breaking all subsequent handshakes, metadata fetches, notify and probe requests.
Published: 2026-10-01
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

Mooncake transfer engine version 0.3.13.post1 contains a remote denial of service flaw that allows unauthenticated attackers to exploit the P2P Handshake Daemon by sending a crafted Metadata request to the RPC port. The request never reads replies, causing the SocketHandShakePlugin’s single listener thread in writeFully() to block. This blocks all subsequent handshakes, metadata fetches, notifications, and probe requests, effectively stopping the peer‑to‑peer transfer service.

Affected Systems

The vulnerability affects the Mooncake transfer engine from the kvcache‑ai vendor. Any deployment running 0.3.13.post1 or an earlier build is exposed; newer versions may be unaffected if a patch has been applied.

Risk and Exploitability

The CVSS score of 8.2 reflects high severity, and the absence of an authentication requirement makes the attack path straightforward over the network. The flaw is a classic resource‑exhaustion issue (CWE‑400). Although EPSS information is unavailable, the lack of a KEV listing does not diminish the risk for systems that rely on continuous peer‑to‑peer data transfer, as a single remote request can bring the handshake daemon to a halt.

Generated by OpenCVE AI on October 2, 2026 at 01:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Mooncake release that contains the denial‑of‑service fix, if available.
  • Restrict network access to the Mooncake handshake RPC port to only trusted peers or via firewall ACLs, preventing unauthenticated traffic.
  • Enable or implement connection timeouts and enforce maximum pending requests on the handshake listener to mitigate denial‑of‑service loops.

Generated by OpenCVE AI on October 2, 2026 at 01:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Kvcache-ai
Kvcache-ai mooncake
Vendors & Products Kvcache-ai
Kvcache-ai mooncake

Thu, 01 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
Description Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers can send a Metadata request to the handshake RPC port and stall SocketHandShakePlugin's single listener thread in writeFully(), breaking all subsequent handshakes, metadata fetches, notify and probe requests.
Title Mooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Handshake Daemon Response Write
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Kvcache-ai Mooncake
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T22:53:05.201Z

Reserved: 2026-10-01T10:39:47.845Z

Link: CVE-2026-103760

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T23:16:46.817

Modified: 2026-10-01T23:16:46.817

Link: CVE-2026-103760

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T01:30:07Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption