Impact
Mooncake transfer engine version 0.3.13.post1 contains a remote denial of service flaw that allows unauthenticated attackers to exploit the P2P Handshake Daemon by sending a crafted Metadata request to the RPC port. The request never reads replies, causing the SocketHandShakePlugin’s single listener thread in writeFully() to block. This blocks all subsequent handshakes, metadata fetches, notifications, and probe requests, effectively stopping the peer‑to‑peer transfer service.
Affected Systems
The vulnerability affects the Mooncake transfer engine from the kvcache‑ai vendor. Any deployment running 0.3.13.post1 or an earlier build is exposed; newer versions may be unaffected if a patch has been applied.
Risk and Exploitability
The CVSS score of 8.2 reflects high severity, and the absence of an authentication requirement makes the attack path straightforward over the network. The flaw is a classic resource‑exhaustion issue (CWE‑400). Although EPSS information is unavailable, the lack of a KEV listing does not diminish the risk for systems that rely on continuous peer‑to‑peer data transfer, as a single remote request can bring the handshake daemon to a halt.
OpenCVE Enrichment