Uncontrolled Memory Allocation in MCP Kotlin SDK by Model Context Protocol
CVE-2026-108714
8.7HIGH
What is CVE-2026-108714?
The MCP Kotlin SDK up to version 0.15.0 is vulnerable to an uncontrolled memory allocation issue due to the installation of Ktor WebSockets without setting a maxFrameSize limit. This flaw allows remote attackers to send carefully crafted frame headers with payloads approaching 2 GiB over existing connections. As a result, the application may allocate excessive memory on the server, potentially leading to a denial of service condition. Immediate remediation is required to prevent misuse of this vulnerability.
Affected Version(s)
kotlin-sdk 0 <= 0.15.0
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
