THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-9pj6-vhgr-3mwh (high) — RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service

[GHSA] GHSA-9pj6-vhgr-3mwh (high) — RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service

highgithub_advisoriesPublished 2026-09-16

GHSA-9pj6-vhgr-3mwh Severity: high CVE: CVE-2026-63128

RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service

### Summary

An unauthenticated remote attacker can leak one entry per HTTP request out of the in-memory session table of `LocalSessionManager` by sending a well-formed JSON-RPC `POST` that is *not* an `InitializeRequ

Indicators of compromise

Original source: https://github.com/advisories/GHSA-9pj6-vhgr-3mwh