Modelcontextprotocol / Ruby-Sdk
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-67432 | MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport | HIGH | 7.5 | Jul 29, 2026 |
| CVE-2026-67431 | MCP Ruby SDK: Ruby SSE Session Poisoning | HIGH | 8.3 | Jul 29, 2026 |
| CVE-2026-63119 | MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS) | MEDIUM | 6.2 | Jul 29, 2026 |
| CVE-2026-67430 | MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood | MEDIUM | 5.3 | Jul 29, 2026 |
| CVE-2026-63118 | MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection | MEDIUM | 6.9 | Jul 29, 2026 |
| CVE-2026-33946 | MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay | HIGH | 8.2 | Mar 27, 2026 |
Showing 1 to 6 of 6 CVEs