<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Mooncake Transfer Engine (&lt;= 0.3.13.post1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/mooncake-transfer-engine--0.3.13.post1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 00:19:56 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/mooncake-transfer-engine--0.3.13.post1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Memory Exhaustion Vulnerability in Mooncake Transfer Engine</title><link>https://feed.craftedsignal.io/briefs/2026-10-mooncake-dos/</link><pubDate>Fri, 02 Oct 2026 00:19:56 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-mooncake-dos/</guid><description>An unauthenticated memory exhaustion vulnerability in the Mooncake transfer engine (CVE-2026-103761) allows remote attackers to trigger a denial-of-service condition by repeatedly sending large notify frames to the handshake RPC port.</description><content:encoded><![CDATA[<p>The Mooncake transfer engine, in versions up to and including 0.3.13.post1, is susceptible to a memory exhaustion vulnerability located within the TransferMetadata::receivePeerNotify function. This vulnerability stems from a lack of bounds checking on the notifys vector, which handles incoming peer notification frames. An unauthenticated attacker can exploit this by repeatedly transmitting 1 MB notify frames to the handshake RPC port. Because the system does not cap the size or count of these frames, the process memory usage grows monotonically until the operating system's out-of-memory (OOM) killer is invoked to terminate the engine. This results in a persistent denial-of-service condition, impacting the availability of the transfer service. Defenders should prioritize updating to the next patched release once available and implement rate limiting on the RPC handshake port to mitigate exploitation attempts.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in the immediate termination of the Mooncake transfer engine process via the system OOM killer, causing a denial-of-service. This impacts any infrastructure relying on Mooncake for data transfer operations. No data modification or execution is currently associated with this memory exhaustion vulnerability, but the interruption of service could disrupt critical business processes.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor RPC traffic to the handshake port for high volumes of large frames (1 MB) originating from unauthorized sources.</li>
<li>Apply network-level rate limiting or connection throttling on the handshake RPC port as an immediate defensive measure.</li>
<li>Monitor system logs for OOM killer events or unexpected crashes of the Mooncake process.</li>
<li>Upgrade the Mooncake transfer engine to a version beyond 0.3.13.post1 immediately upon vendor release.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>denial-of-service</category><category>vulnerability</category><category>network</category></item></channel></rss>