Uncontrolled Memory Allocation in MCP Kotlin SDK by Model Context Protocol
CVE-2026-108714

8.7HIGH

Key Information:

Vendor
CVE Published:
11 October 2026

What is CVE-2026-108714?

The MCP Kotlin SDK up to version 0.15.0 is vulnerable to an uncontrolled memory allocation issue due to the installation of Ktor WebSockets without setting a maxFrameSize limit. This flaw allows remote attackers to send carefully crafted frame headers with payloads approaching 2 GiB over existing connections. As a result, the application may allocate excessive memory on the server, potentially leading to a denial of service condition. Immediate remediation is required to prevent misuse of this vulnerability.

Affected Version(s)

kotlin-sdk 0 <= 0.15.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.