Vulnerability  ·  2026-10-12

mcp-go: StreamableHTTPServer buffers unbounded POST bodies → remote OOM DoS of MCP servers (CVSS 7.5)

VulnerabilityMedium impactGlobalCVE-2026-108859
VulnCheck published CVE-2026-108859 (published 2026-10-11, CVSS 7.5 v3.1 / 8.7 v4.0, CWE-770) for mark3labs/mcp-go ≤ 1.2.1: ServeHTTP reads request bodies fully and unbounded before validation, so a remote attacker can degrade or OOM-kill the server with sized/concurrent POST requests. Verified against NVD REST API.
mcp-go is one of the most-used MCP server SDKs in Go; an unauthenticated remote DoS strikes the agent tool-calling layer. Authenticated-by-default MPI servers are still reachable pre-auth at the HTTP layer, so exposure to the network means a cheap availability kill against agent infrastructure.
Remote unauthenticated attacker sends arbitrarily large or many concurrent POST bodies to the StreamableHTTPServer, which reads the full body via io.ReadAll before any size validation, exhausting memory.
github.com/mark3labs/mcp-go through 1.2.1
Upgrade mcp-go past 1.2.1 and/or enforce request-size limits at a reverse proxy in front of MCP servers. Advisory: https://www.vulncheck.com/advisories/mcp-go-through-1.2.1-denial-of-service-via-unbounded-post-body-buffering
NVD CVE-2026-108859VulnCheck advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →