{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3amcp-gomcp-go/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mcp-go:mcp-go:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-108859"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["mcp-go (\u003c= 1.2.1)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003emcp-go versions through 1.2.1 are susceptible to a denial of service (DoS) vulnerability located within the StreamableHTTPServer.ServeHTTP function. The vulnerability is caused by an unsafe implementation where the server reads the entirety of an incoming POST request body into memory using the io.ReadAll function before any validation logic is executed. This design flaw allows remote, unauthenticated attackers to transmit either a single arbitrarily large POST body or multiple concurrent requests, rapidly consuming the available memory of the host process. Successful exploitation leads to memory exhaustion, causing the server process to crash or be terminated by the operating system's out-of-memory (OOM) killer. This impacts the availability of any service relying on the mcp-go library for handling HTTP streams.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in a denial of service for the affected application. Because the impact is memory exhaustion, the entire service process may terminate, requiring manual intervention or automated restart procedures to recover. This affects any infrastructure or internal service components that have integrated mcp-go versions 1.2.1 or earlier for handling HTTP communication.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the mcp-go library to a version later than 1.2.1 where request body validation occurs prior to buffering or where memory limits are enforced during read operations.\u003c/li\u003e\n\u003cli\u003eImplement request body size limits at the load balancer or reverse proxy layer (e.g., Nginx client_max_body_size) to prevent excessively large payloads from reaching the application server.\u003c/li\u003e\n\u003cli\u003eAudit custom HTTP server implementations using mcp-go to ensure that io.ReadAll is not used on unvalidated request streams.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-11T16:02:48Z","date_published":"2026-10-11T16:02:48Z","id":"https://feed.craftedsignal.io/briefs/2026-10-mcp-go-dos/","summary":"mcp-go versions through 1.2.1 contain a denial of service vulnerability in StreamableHTTPServer.ServeHTTP that allows remote, unauthenticated attackers to trigger memory exhaustion via oversized POST request bodies.","title":"Denial of Service Vulnerability in mcp-go","url":"https://feed.craftedsignal.io/briefs/2026-10-mcp-go-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:mcp-Go:mcp-Go:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}