top of page
perceptive_background_267k.jpg

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the m…

Published:

29 juli 2026 om 00:00:00

Alert date:

29 juli 2026 om 23:00:58

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies, Emerging Technologies

CVE-2026-67432 affects the MCP Ruby SDK (mcp gem) prior to version 0.23.0. The vulnerability resides in MCP::Server::Transports::StreamableHTTPTransport, which reads and parses entire JSON-RPC POST request bodies without enforcing any size limit. This allows an unauthenticated remote attacker to send arbitrarily large payloads, exhausting the server process memory and causing a denial of service. The issue is classified as a resource exhaustion vulnerability with no authentication required for exploitation. The fix was introduced in version 0.23.0 of the mcp gem. Affected users should upgrade immediately to mitigate the risk. The vulnerability was disclosed via GitHub Security Advisories and the NVD.

Technical details

Mitigation steps:

Affected products:

MCP Ruby SDK (mcp gem)
MCP::Server::Transports::StreamableHTTPTransport

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page