CVE-2026-103760
EUVD-2026-9113401.10.2026, 23:16
Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers can send a Metadata request to the handshake RPC port and stall SocketHandShakePlugin's single listener thread in writeFully(), breaking all subsequent handshakes, metadata fetches, notify and probe requests.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
References