What happened
VulnCheck published CVE-2026-108859 (published 2026-10-11, CVSS 7.5 v3.1 / 8.7 v4.0, CWE-770) for mark3labs/mcp-go ≤ 1.2.1: ServeHTTP reads request bodies fully and unbounded before validation, so a remote attacker can degrade or OOM-kill the server with sized/concurrent POST requests. Verified against NVD REST API.
Why it matters
mcp-go is one of the most-used MCP server SDKs in Go; an unauthenticated remote DoS strikes the agent tool-calling layer. Authenticated-by-default MPI servers are still reachable pre-auth at the HTTP layer, so exposure to the network means a cheap availability kill against agent infrastructure.
Attack vector
Remote unauthenticated attacker sends arbitrarily large or many concurrent POST bodies to the StreamableHTTPServer, which reads the full body via io.ReadAll before any size validation, exhausting memory.
Affected systems
github.com/mark3labs/mcp-go through 1.2.1
Mitigation
Upgrade mcp-go past 1.2.1 and/or enforce request-size limits at a reverse proxy in front of MCP servers. Advisory: https://www.vulncheck.com/advisories/mcp-go-through-1.2.1-denial-of-service-via-unbounded-post-body-buffering