CVE-2026-103760 HIGH

CVE-2026-103760: Mooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Handshake Daemon Response Write

Vendor Kvcache-Ai
Product Mooncake
Weakness CWE-400
Published October 1, 2026
Last update October 2, 2026

CVSS base score

8.2/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers can send a Metadata request to the handshake RPC port and stall SocketHandShakePlugin's single listener thread in writeFully(), breaking all subsequent handshakes, metadata fetches, notify and probe requests.

Key dates

02Disclosure timeline

October 1, 2026 CVE published
October 2, 2026 Record updated