Back to CVE List

CVE-2026-67430

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
5.3 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Vulnerability Description

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not expire sessions by default, so repeated initialize requests retain unbounded ServerSession objects and can exhaust process memory. This issue is fixed in version 0.23.0.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-401
Source
NVD
Vendor
modelcontextprotocol
Product
ruby-sdk

External References

Discussion (0)

Add Comment

No comments yet. Be the first!