{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/mooncake/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mooncake:mooncake_store:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-106040"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Mooncake Store (\u003c= 0.3.13.post1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Mooncake"],"content_html":"\u003cp\u003eMooncake Store versions up to and including 0.3.13.post1 contain a missing authorization vulnerability (CVE-2026-106040). This flaw resides within the coro_rpc master port functionality, which fails to enforce access control checks for sensitive operations. Unauthenticated remote attackers can connect to the exposed master port and invoke the EvictDiskReplica or BatchEvictDiskReplica functions. By successfully executing these functions, an attacker can force the system to evict disk replicas across all tenants. This vulnerability is significant because if a disk replica is the sole remaining copy of an object, invoking these functions results in permanent data loss for those objects. Defenders should restrict network access to the coro_rpc master port to trusted management subnets and upgrade to a patched version once available.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to perform unauthorized administrative actions against the storage infrastructure. The primary impact is the potential for permanent data loss across all tenants if an attacker targets objects where the disk replica is the unique surviving copy, leading to widespread service degradation or data destruction.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestrict network access to the coro_rpc master port to only authorized management IPs at the network firewall layer.\u003c/li\u003e\n\u003cli\u003eAudit access logs for unexpected or unauthorized connections originating from non-management subnets targeting the coro_rpc service.\u003c/li\u003e\n\u003cli\u003eMonitor for abnormally high volumes of calls to EvictDiskReplica or BatchEvictDiskReplica functions, as these may indicate malicious activity or system abuse.\u003c/li\u003e\n\u003cli\u003eUpdate Mooncake Store to a version greater than 0.3.13.post1 as soon as a security update is released by the vendor to address the missing authorization logic.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T14:56:28Z","date_published":"2026-10-06T14:56:28Z","id":"https://feed.craftedsignal.io/briefs/2026-10-mooncake-store-missing-auth/","summary":"Mooncake Store versions up to 0.3.13.post1 are vulnerable to a missing authorization flaw in the coro_rpc master port that allows unauthenticated attackers to trigger unauthorized object deletion via replica eviction.","title":"Unauthenticated Disk Replica Eviction in Mooncake Store","url":"https://feed.craftedsignal.io/briefs/2026-10-mooncake-store-missing-auth/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mooncake:transfer_engine:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-103761"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Mooncake transfer engine (\u003c= 0.3.13.post1)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","vulnerability","network"],"_cs_type":"advisory","_cs_vendors":["Mooncake"],"content_html":"\u003cp\u003eThe Mooncake transfer engine, in versions up to and including 0.3.13.post1, is susceptible to a memory exhaustion vulnerability located within the TransferMetadata::receivePeerNotify function. This vulnerability stems from a lack of bounds checking on the notifys vector, which handles incoming peer notification frames. An unauthenticated attacker can exploit this by repeatedly transmitting 1 MB notify frames to the handshake RPC port. Because the system does not cap the size or count of these frames, the process memory usage grows monotonically until the operating system's out-of-memory (OOM) killer is invoked to terminate the engine. This results in a persistent denial-of-service condition, impacting the availability of the transfer service. Defenders should prioritize updating to the next patched release once available and implement rate limiting on the RPC handshake port to mitigate exploitation attempts.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the immediate termination of the Mooncake transfer engine process via the system OOM killer, causing a denial-of-service. This impacts any infrastructure relying on Mooncake for data transfer operations. No data modification or execution is currently associated with this memory exhaustion vulnerability, but the interruption of service could disrupt critical business processes.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor RPC traffic to the handshake port for high volumes of large frames (1 MB) originating from unauthorized sources.\u003c/li\u003e\n\u003cli\u003eApply network-level rate limiting or connection throttling on the handshake RPC port as an immediate defensive measure.\u003c/li\u003e\n\u003cli\u003eMonitor system logs for OOM killer events or unexpected crashes of the Mooncake process.\u003c/li\u003e\n\u003cli\u003eUpgrade the Mooncake transfer engine to a version beyond 0.3.13.post1 immediately upon vendor release.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T00:19:56Z","date_published":"2026-10-02T00:19:56Z","id":"https://feed.craftedsignal.io/briefs/2026-10-mooncake-dos/","summary":"An unauthenticated memory exhaustion vulnerability in the Mooncake transfer engine (CVE-2026-103761) allows remote attackers to trigger a denial-of-service condition by repeatedly sending large notify frames to the handshake RPC port.","title":"Memory Exhaustion Vulnerability in Mooncake Transfer Engine","url":"https://feed.craftedsignal.io/briefs/2026-10-mooncake-dos/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mooncake:transfer_engine:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-103764"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["transfer engine (\u003c 0.3.13)","transfer engine (\u003c 0.3.12)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","rce","memory-corruption"],"_cs_type":"advisory","_cs_vendors":["Mooncake"],"content_html":"\u003cp\u003eThe Mooncake transfer engine prior to version 0.3.13 is susceptible to an untrusted pointer dereference vulnerability residing in the ServerSession::readHeader function. This flaw allows unauthenticated remote attackers to interact with the service over its TCP transport data port. By crafting a malicious SessionHeader containing arbitrary address and size fields, an attacker can issue READ or WRITE opcodes. These operations enable the unauthorized disclosure of sensitive internal information, such as KV cache contents, prompts, and system secrets. Furthermore, the ability to perform arbitrary memory writes allows for potential memory corruption, which may be leveraged to achieve remote code execution on the host running the transfer engine. Given the severity of this vulnerability and the lack of authentication requirements, defenders should prioritize patching to version 0.3.13 or later.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-103764 results in full compromise of the affected process memory. Impact includes the theft of sensitive proprietary data, such as cached prompts and secrets, and potential full system compromise via arbitrary code execution. This impacts any environment deploying Mooncake transfer engine versions prior to 0.3.13 exposed to untrusted network segments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Mooncake transfer engine to version 0.3.13 or later immediately to address the underlying pointer dereference flaw.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the Mooncake TCP transport data port to trusted IP addresses only, reducing the attack surface until patches can be applied.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic for anomalous sequences targeting the transfer engine port, specifically looking for header anomalies or large-scale data transfer patterns indicative of memory dumping.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-03T00:49:42Z","date_published":"2026-10-02T00:19:35Z","id":"https://feed.craftedsignal.io/briefs/2026-10-mooncake-memory-corruption/","summary":"An untrusted pointer dereference vulnerability (CVE-2026-103764) in the Mooncake transfer engine allows unauthenticated attackers to perform arbitrary memory reads and writes, potentially leading to remote code execution.","title":"Arbitrary Memory Access Vulnerability in Mooncake Transfer Engine","url":"https://feed.craftedsignal.io/briefs/2026-10-mooncake-memory-corruption/"}],"language":"en","title":"CraftedSignal Threat Feed - Mooncake","version":"https://jsonfeed.org/version/1.1"}