CVE-2026-108714
Received Received - Intake

Uncontrolled Memory Allocation in MCP Kotlin SDK

Vulnerability report for CVE-2026-108714, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

MCP Kotlin SDK through 0.15.0 contains an uncontrolled memory allocation vulnerability that allows remote clients to exhaust server memory because Application.mcpWebSocket installs Ktor WebSockets without a maxFrameSize limit. Attackers can send small frame headers declaring payloads near 2 GiB over one or a few connections, forcing huge heap allocations and causing denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
modelcontextprotocol kotlin-sdk 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MCP Kotlin SDK through version 0.15.0 has an uncontrolled memory allocation flaw. The Application.mcpWebSocket component uses Ktor WebSockets without setting a maximum frame size limit. Attackers can exploit this by sending small frame headers that declare payloads near 2 GiB over one or a few connections. This forces the server to allocate large amounts of memory, leading to a denial of service.

Detection Guidance

Monitor for unusually large memory allocations or sudden memory exhaustion on systems running MCP Kotlin SDK through 0.15.0. Check WebSocket connections for frames with large declared payload sizes without corresponding data. Use system monitoring tools like top, htop, or ps to observe memory usage spikes.

Impact Analysis

This vulnerability can cause your server to run out of memory, leading to crashes or unresponsiveness. If exploited, it may disrupt services relying on the MCP Kotlin SDK, resulting in downtime and potential loss of availability for applications using this SDK.

Compliance Impact

This vulnerability primarily impacts availability by causing denial of service through memory exhaustion. It does not directly affect confidentiality or integrity of data, which are key concerns for GDPR and HIPAA. However, prolonged downtime could indirectly impact compliance by disrupting access to personal or health data processing systems.

Mitigation Strategies

Upgrade MCP Kotlin SDK to a version that sets a maxFrameSize limit for Ktor WebSockets. If upgrading is not immediately possible, implement network-level protections to limit WebSocket frame sizes or block suspicious connections. Restrict access to vulnerable services until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108714. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart