CPE
The MCP Kotlin SDK through version 0.15.0 is vulnerable to denial of service due to the absence of a maxFrameSize limit in the Ktor WebSocket configuration, allowing remote clients to trigger heap exhaustion.