CVE-2026-108859
Deferred Deferred - Pending Action

Memory Exhaustion in MCP-Go StreamableHTTPServer

Vulnerability report for CVE-2026-108859, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

mcp-go through 1.2.1 contains a denial of service vulnerability in StreamableHTTPServer.ServeHTTP that allows remote unauthenticated attackers to exhaust memory by sending oversized POST bodies. Attackers can send arbitrarily large or many concurrent POST requests, read fully via io.ReadAll before validation, to degrade or OOM-kill the server process.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mark3labs mcp-go 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

mcp-go through version 1.2.1 has a denial of service vulnerability in the StreamableHTTPServer.ServeHTTP function. Remote unauthenticated attackers can exploit this by sending oversized POST request bodies, causing the server to exhaust memory resources. The issue occurs because the server reads the entire POST body via io.ReadAll before validating its size, allowing attackers to send arbitrarily large or numerous requests to degrade performance or crash the server process.

Detection Guidance

Monitor for unusually high memory usage or server crashes when handling POST requests. Check server logs for large or frequent POST requests. Use tools like netstat or ss to observe incoming connections.

Impact Analysis

This vulnerability can impact you by causing your mcp-go server to become unresponsive or crash due to memory exhaustion. Attackers could exploit this to degrade service quality, disrupt operations, or force downtime for applications relying on the affected server. Systems with limited memory resources are particularly vulnerable to this type of attack.

Compliance Impact

This vulnerability may impact compliance with GDPR and HIPAA by potentially causing service disruptions or data processing interruptions. GDPR requires ensuring availability of processing systems, while HIPAA mandates safeguards against unauthorized access or disruptions. A denial of service could violate these requirements, leading to compliance risks or penalties if not addressed.

Mitigation Strategies

Upgrade mcp-go to a version beyond 1.2.1. Implement request size limits and validate POST body sizes before processing. Use rate limiting to prevent excessive requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108859. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart