CVE-2026-103760: Mooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Handshake Daemon Response Write
Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers can send a Metadata request to the handshake RPC port and stall SocketHandShakePlugin's single listener thread in writeFully(), breaking all subsequent handshakes, metadata fetches, notify and probe requests.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this denial of service?
Deployments running Mooncake transfer engine through 0.3.13.post1 are exposed if an unauthenticated remote attacker can reach the handshake RPC port.
What does an attacker need to do to trigger the condition?
The attacker sends a Metadata request to the handshake RPC port and then does not read the daemon's reply. This can stall the SocketHandShakePlugin single listener thread in writeFully().
What service impact should responders expect?
Once the listener thread is blocked, subsequent handshakes, metadata fetches, notify requests, and probe requests can fail or stop being processed.