CVE-2026-103760

⚪ Do wiadomości

W Mooncake transfer engine występuje podatność na odmowę usługi, umożliwiająca zdalnym atakującym zablokowanie demona handshake.

CVSS
5.9
EPSS
0.4%
Exploit
none
Vendor
Opis źródłowy (NVD)

Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers can send a Metadata request to the handshake RPC port and stall SocketHandShakePlugin's single listener thread in writeFully(), breaking all subsequent handshakes, metadata fetches, notify and probe requests.

dos Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.9
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.4%
Opublikowano (NVD)2026-10-01 23:16:46 UTC
Ostatnia modyfikacja (NVD)2026-10-02 18:00:34 UTC
Referencje