Denial of Service Vulnerability in mcp-go by Mark3Labs
CVE-2026-108859

8.7HIGH

Key Information:

Vendor

Mark3labs

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-108859?

mcp-go versions up to 1.2.1 are susceptible to a denial of service vulnerability found in the StreamableHTTPServer.ServeHTTP method. This issue allows remote, unauthenticated attackers to exploit the system by sending oversized POST requests. Attackers can overwhelm server resources by sending excessively large request bodies, which are read in their entirety before any validation takes place. This could lead to significant memory exhaustion, potentially culminating in the server process being terminated due to out-of-memory conditions. Proper input validation and request body size limitations are critical to mitigating this vulnerability.

Affected Version(s)

mcp-go 0 <= 1.2.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hieuPenguinnn
.