CVE-2026-103760: Mooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Handshake Daemon Response Write

Published Oct 1, 2026
·
Updated

Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers can send a Metadata request to the handshake RPC port and stall SocketHandShakePlugin's single listener thread in writeFully(), breaking all subsequent handshakes, metadata fetches, notify and probe requests.

Affected Software

1 affected component
pypi/mooncake-transfer-engine<=0.3.13.post1

Event History

Oct 1, 2026
CVE Published
via MITRE·10:53 PM
Data Sourced
via MITRE·10:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeakness
May 11, 58721
Event
via NVD·12:04 AM

Frequently Asked Questions

1

Which deployments are exposed to this denial of service?

Deployments running Mooncake transfer engine through 0.3.13.post1 are exposed if an unauthenticated remote attacker can reach the handshake RPC port.

2

What does an attacker need to do to trigger the condition?

The attacker sends a Metadata request to the handshake RPC port and then does not read the daemon's reply. This can stall the SocketHandShakePlugin single listener thread in writeFully().

3

What service impact should responders expect?

Once the listener thread is blocked, subsequent handshakes, metadata fetches, notify requests, and probe requests can fail or stop being processed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203