CVE-2026-103760 UNKNOWN

CVE-2026-103760

Published: 2026-10-01

Description

Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers can send a Metadata request to the handshake RPC port and stall SocketHandShakePlugin's single listener thread in writeFully(), breaking all subsequent handshakes, metadata fetches, notify and probe requests.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…