


Perceptive Security
SOC/SIEM Consultancy

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the m…
Published:
29 July 2026 at 00:00:00
Alert date:
29 July 2026 at 23:00:58
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies, Emerging Technologies
CVE-2026-67432 affects the MCP Ruby SDK (mcp gem) prior to version 0.23.0. The vulnerability resides in MCP::Server::Transports::StreamableHTTPTransport, which reads and parses entire JSON-RPC POST request bodies without enforcing any size limit. This allows an unauthenticated remote attacker to send arbitrarily large payloads, exhausting the server process memory and causing a denial of service. The issue is classified as a resource exhaustion vulnerability with no authentication required for exploitation. The fix was introduced in version 0.23.0 of the mcp gem. Affected users should upgrade immediately to mitigate the risk. The vulnerability was disclosed via GitHub Security Advisories and the NVD.
Technical details
Mitigation steps:
Affected products:
MCP Ruby SDK (mcp gem)
MCP::Server::Transports::StreamableHTTPTransport
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67432
https://github.com/modelcontextprotocol/ruby-sdk/commit/772e0cb1f9db69312006926eee59a7287ad50166
https://github.com/modelcontextprotocol/ruby-sdk/releases/tag/v0.23.0
https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-h669-8m4g-r2hc
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
