Denial of Service Vulnerability in mcp-go by Mark3Labs
CVE-2026-108859
8.7HIGH
What is CVE-2026-108859?
mcp-go versions up to 1.2.1 are susceptible to a denial of service vulnerability found in the StreamableHTTPServer.ServeHTTP method. This issue allows remote, unauthenticated attackers to exploit the system by sending oversized POST requests. Attackers can overwhelm server resources by sending excessively large request bodies, which are read in their entirety before any validation takes place. This could lead to significant memory exhaustion, potentially culminating in the server process being terminated due to out-of-memory conditions. Proper input validation and request body size limitations are critical to mitigating this vulnerability.
Affected Version(s)
mcp-go 0 <= 1.2.1
