Memory Exhaustion Vulnerability in MKP for Kubernetes
CVE-2026-50125
7.5HIGH
What is CVE-2026-50125?
The MKP (Model Context Protocol) server for Kubernetes exposes a vulnerability that allows unauthenticated remote attackers to exploit unbounded parameters resulting in memory exhaustion. This occurs through an HTTP endpoint that accepts parameters for pod log retrieval, specifically the limitBytes and tailLines values. Attackers can manipulate these parameters to request excessively large log streams, leading to unsustainable memory allocations that can crash the MKP server and disrupt service availability. This issue has been addressed in version 0.4.1, emphasizing the importance of upgrading to mitigate such risks.
Affected Version(s)
mkp < 0.4.1
