High severity7.5NVD Advisory· Published Oct 11, 2026· Updated Oct 11, 2026
CVE-2026-108859
CVE-2026-108859
Description
mcp-go through 1.2.1 contains a denial of service vulnerability in StreamableHTTPServer.ServeHTTP that allows remote unauthenticated attackers to exhaust memory by sending oversized POST bodies. Attackers can send arbitrarily large or many concurrent POST requests, read fully via io.ReadAll before validation, to degrade or OOM-kill the server process.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.