CVE-2026-103760
published 2026-10-01CVE-2026-103760: Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake…
PriorityP335medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
0.40%
32.0th percentile
Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers can send a Metadata request to the handshake RPC port and stall SocketHandShakePlugin's single listener thread in writeFully(), breaking all subsequent handshakes, metadata fetches, notify and probe requests.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| kvcache-ai | mooncake | <= 0.3.13.post1 | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.2HIGHCVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies.
ghsa_unreviewed·2026-10-02
CVE-2026-103760 [HIGH] CWE-400 Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies.
Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers can send a Metadata request to the handshake RPC port and stall SocketHandShakePlugin's single listener thread in writeFully(), breaking all subsequent handshakes, metadata fetches, notify and probe requests.
VulDB
kvcache-ai Mooncake up to 0.3.13.post1 SocketHandShakePlugin writeFully denial of service (EUVD-2026-91134)
vuldb·2026-10-02·CVSS 5.9
CVE-2026-103760 [MEDIUM] kvcache-ai Mooncake up to 0.3.13.post1 SocketHandShakePlugin writeFully denial of service (EUVD-2026-91134)
A vulnerability was found in kvcache-ai Mooncake up to 0.3.13.post1 and classified as problematic. This impacts the function writeFully of the component SocketHandShakePlugin. Such manipulation leads to denial of service.
This vulnerability is referenced as CVE-2026-103760. It is possible to launch the attack remotely. No exploit is available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/kvcache-ai/Mooncakehttps://github.com/kvcache-ai/Mooncake/blob/719735896c86b56fabec6cf3e825fb2ea640597a/mooncake-transfer-engine/src/transfer_metadata_plugin.cpp#L730-L803https://github.com/kvcache-ai/Mooncake/issues/4443https://www.vulncheck.com/advisories/mooncake-transfer-engine-through-0.3.13-post1-denial-of-service-via-p2p-handshake-daemon-response-writehttps://github.com/kvcache-ai/Mooncake/issues/4443
2026-10-01
Published