Memory Exhaustion Vulnerability in MKP for Kubernetes
CVE-2026-50125

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-50125?

The MKP (Model Context Protocol) server for Kubernetes exposes a vulnerability that allows unauthenticated remote attackers to exploit unbounded parameters resulting in memory exhaustion. This occurs through an HTTP endpoint that accepts parameters for pod log retrieval, specifically the limitBytes and tailLines values. Attackers can manipulate these parameters to request excessively large log streams, leading to unsustainable memory allocations that can crash the MKP server and disrupt service availability. This issue has been addressed in version 0.4.1, emphasizing the importance of upgrading to mitigate such risks.

Affected Version(s)

mkp < 0.4.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.