THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-52jp-gj8w-j6xh (medium) — MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood

[GHSA] GHSA-52jp-gj8w-j6xh (medium) — MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood

highgithub_advisoriesPublished 2026-07-30

GHSA-52jp-gj8w-j6xh Severity: medium CVE: CVE-2026-67430

MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood

## Summary

In its default configuration, `MCP::Server::Transports::StreamableHTTPTransport` never expires sessions. Every successful `initialize` request stores a new `ServerSession` and a session record under a fresh UUID, a

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-52jp-gj8w-j6xh