THREAT OPS › Threat News › [GHSA] GHSA-9pj6-vhgr-3mwh (high) — RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service
[GHSA] GHSA-9pj6-vhgr-3mwh (high) — RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service
GHSA-9pj6-vhgr-3mwh Severity: high CVE: CVE-2026-63128
RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service
### Summary
An unauthenticated remote attacker can leak one entry per HTTP request out of the in-memory session table of `LocalSessionManager` by sending a well-formed JSON-RPC `POST` that is *not* an `InitializeRequ
Indicators of compromise
- CVE-2026-63128cve
- CVE-2026-42559cve
- http://{BIND_ADDRESS}/mcpurl
- http://127.0.0.1:8000/mcpurl
- http://{HOST}:{PORT}{PATH}url
Original source: https://github.com/advisories/GHSA-9pj6-vhgr-3mwh