Vulnerability  ·  2026-10-12

MCP Kotlin SDK: WebSocket transport without maxFrameSize allows memory-exhaustion DoS of MCP servers (CVSS 7.5)

VulnerabilityMedium impactGlobalCVE-2026-108714
VulnCheck published CVE-2026-108714 (published 2026-10-11, CVSS 7.5 v3.1 / 8.7 v4.0, CWE-770) for the official MCP Kotlin SDK ≤ 0.15.0: Application.mcpWebSocket installs Ktor WebSockets without a maxFrameSize limit, so a small controlled frame header can trigger multi-GiB allocations over a couple of connections, taking MCP servers down. Verified against NVD REST API.
Kotlin SDK powers production MCP servers across the agent ecosystem; an unauthenticated remote DoS against MCP infrastructure takes agent tool-calling surfaces offline and can crash shared model-serving/agent hosts — a cheap availability attack on agent deployments that exposes MCP to the network.
Remote unauthenticated client opens one or a few WebSocket connections to an MCP server and sends frames whose headers declare payloads near 2 GiB (no maxFrameSize configured in the Ktor WebSocket install), forcing huge heap allocations and exhausting server memory.
MCP Kotlin SDK (io.modelcontextprotocol:kotlin-sdk-server) through 0.15.0
Upgrade the Kotlin MCP SDK past 0.15.0 (or set an explicit WebSocket maxFrameSize via the transport config); place MCP endpoints behind auth/reverse proxy with body-size limits. Advisory: https://www.vulncheck.com/advisories/mcp-kotlin-sdk-through-0.15.0-memory-exhaustion-via-application-mcpwebsocket
NVD CVE-2026-108714VulnCheck advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →