Vendor
high
advisory
Unauthenticated Disk Replica Eviction in Mooncake Store
1 TTP 1 CVEMooncake Store versions up to 0.3.13.post1 are vulnerable to a missing authorization flaw in the coro_rpc master port that allows unauthenticated attackers to trigger unauthorized object deletion via replica eviction.
Mooncake Store
1t
1c
low
advisory
Memory Exhaustion Vulnerability in Mooncake Transfer Engine
1 TTP 1 CVEAn unauthenticated memory exhaustion vulnerability in the Mooncake transfer engine (CVE-2026-103761) allows remote attackers to trigger a denial-of-service condition by repeatedly sending large notify frames to the handshake RPC port.
Mooncake transfer engine
denial-of-service
vulnerability
network
1t
1c
critical
advisory
Arbitrary Memory Access Vulnerability in Mooncake Transfer Engine
2 TTPs 1 CVEAn untrusted pointer dereference vulnerability (CVE-2026-103764) in the Mooncake transfer engine allows unauthenticated attackers to perform arbitrary memory reads and writes, potentially leading to remote code execution.
transfer engine +1
vulnerability
rce
memory-corruption
2t
1c
updated