CVE-2026-103761
Received Received - Intake

Memory Exhaustion in Mooncake Transfer Engine

Vulnerability report for CVE-2026-103761, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly send notify frames up to 1 MB to the handshake RPC port, filling the uncapped notifys vector until the out-of-memory killer terminates the engine.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mooncake transfer_engine 0.3.13_post1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Mooncake transfer engine through version 0.3.13.post1 has a memory exhaustion vulnerability in the TransferMetadata::receivePeerNotify function. Unauthenticated attackers can exploit this by sending repeated notify frames up to 1 MB to the handshake RPC port. This causes the notifys vector to grow without limit until the process runs out of memory and is terminated by the system's out-of-memory killer.

Detection Guidance

Monitor for unusually high memory usage in the Mooncake transfer engine process. Check for repeated connections to the handshake RPC port (likely default port) sending large notify frames. Use system monitoring tools like 'top', 'htop', or 'ps' to observe memory consumption spikes in the engine process.

Impact Analysis

This vulnerability can lead to denial-of-service conditions where the Mooncake transfer engine crashes due to excessive memory consumption. Attackers could repeatedly trigger this issue, causing the service to become unavailable and disrupting normal operations that rely on it.

Compliance Impact

This vulnerability could lead to denial-of-service conditions by exhausting system memory, potentially disrupting services handling sensitive data. For GDPR, this may impact availability of personal data processing systems, while for HIPAA, it could affect the integrity and availability of protected health information systems.

Mitigation Strategies

Upgrade Mooncake transfer engine to a version beyond 0.3.13.post1. If upgrading is not immediately possible, restrict network access to the handshake RPC port using firewalls or network policies to prevent unauthenticated connections. Monitor memory usage closely until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103761. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart