THREAT OPS › Threat News › [GHSA] GHSA-h669-8m4g-r2hc (high) — MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
[GHSA] GHSA-h669-8m4g-r2hc (high) — MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
GHSA-h669-8m4g-r2hc Severity: high CVE: CVE-2026-67432
MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
## Summary
An unauthenticated remote attacker can force any MCP Ruby SDK server using `MCP::Server::Transports::StreamableHTTPTransport` to allocate gigabytes of memory by sending a single oversized JSON-RPC POST. The transport rea
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-67432cve
- http://127.0.0.1:9293/url
Original source: https://github.com/advisories/GHSA-h669-8m4g-r2hc