CVE-2026-108859 PUBLISHED

mcp-go through 1.2.1 Denial of Service via Unbounded POST Body Buffering

Assigner: VulnCheck
Reserved: 11.10.2026 Published: 11.10.2026 Updated: 11.10.2026

mcp-go through 1.2.1 contains a denial of service vulnerability in StreamableHTTPServer.ServeHTTP that allows remote unauthenticated attackers to exhaust memory by sending oversized POST bodies. Attackers can send arbitrarily large or many concurrent POST requests, read fully via io.ReadAll before validation, to degrade or OOM-kill the server process.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor mark3labs
Product mcp-go
Versions Default: unaffected
  • affected from 0 to 1.2.1 (incl.)

Credits

  • hieuPenguinnn finder

References

Problem Types

  • Allocation of Resources Without Limits or Throttling CWE