mcp-go through 1.2.1 contains a denial of service vulnerability in StreamableHTTPServer.ServeHTTP that allows remote unauthenticated attackers to exhaust memory by sending oversized POST bodies. Attackers can send arbitrarily large or many concurrent POST requests, read fully via io.ReadAll before validation, to degrade or OOM-kill the server process.

Project Subscriptions

Vendors Products
Mark3labs Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 11 Oct 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Mark3labs
Mark3labs mcp-go
Vendors & Products Mark3labs
Mark3labs mcp-go

Sun, 11 Oct 2026 13:45:00 +0000

Type Values Removed Values Added
Description mcp-go through 1.2.1 contains a denial of service vulnerability in StreamableHTTPServer.ServeHTTP that allows remote unauthenticated attackers to exhaust memory by sending oversized POST bodies. Attackers can send arbitrarily large or many concurrent POST requests, read fully via io.ReadAll before validation, to degrade or OOM-kill the server process.
Title mcp-go through 1.2.1 Denial of Service via Unbounded POST Body Buffering
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T13:26:06.450Z

Reserved: 2026-10-11T13:06:49.278Z

Link: CVE-2026-108859

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-11T14:17:05.780

Modified: 2026-10-11T14:17:05.893

Link: CVE-2026-108859

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T15:00:12Z

Weaknesses