THREAT OPS › Threat News › [GHSA] GHSA-52jp-gj8w-j6xh (medium) — MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood
[GHSA] GHSA-52jp-gj8w-j6xh (medium) — MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood
GHSA-52jp-gj8w-j6xh Severity: medium CVE: CVE-2026-67430
MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood
## Summary
In its default configuration, `MCP::Server::Transports::StreamableHTTPTransport` never expires sessions. Every successful `initialize` request stores a new `ServerSession` and a session record under a fresh UUID, a
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-67430cve
- http://127.0.0.1:9295/url
Original source: https://github.com/advisories/GHSA-52jp-gj8w-j6xh