Moderate severityNVD Advisory· Published Jul 29, 2026· Updated Jul 29, 2026
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)
CVE-2026-63119
Description
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StdioTransport and MCP::Client::Stdio in the mcp gem use IO#gets without a byte limit, allowing a peer that sends data without a newline to exhaust process memory. This issue is fixed in version 0.23.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mcpRubyGems | < 0.23.0 | 0.23.0 |
Affected products
1- Range: <0.23.0
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-7683-3w9x-ch42ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-63119ghsaADVISORY
- github.com/modelcontextprotocol/ruby-sdk/commit/267b8fa6285453525c81ce43db6b7dcd7a8a8c2fghsax_refsource_MISCWEB
- github.com/modelcontextprotocol/ruby-sdk/releases/tag/v0.23.0ghsax_refsource_MISCWEB
- github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-7683-3w9x-ch42ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.