{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3amodel_context_protocolmcp_kotlin_sdk/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:model_context_protocol:mcp_kotlin_sdk:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-108714"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MCP Kotlin SDK (\u003c= 0.15.0)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Model Context Protocol"],"content_html":"\u003cp\u003eThe MCP Kotlin SDK, specifically versions up to and including 0.15.0, contains an uncontrolled memory allocation vulnerability (CVE-2026-108714) within the \u003ccode\u003eApplication.mcpWebSocket\u003c/code\u003e component. The vulnerability arises because the SDK initializes Ktor WebSockets without explicitly configuring a \u003ccode\u003emaxFrameSize\u003c/code\u003e limit. This oversight allows a remote attacker to send crafted WebSocket frame headers that declare very large payload sizes, approaching 2 GiB. By initiating one or a small number of concurrent connections and sending these malformed headers, an attacker can force the server to attempt massive heap allocations, leading to rapid memory exhaustion and a subsequent denial of service (DoS) state. This vulnerability impacts any service utilizing the affected SDK version for WebSocket communication, as the resource consumption occurs before the application logic processes the data.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in an immediate denial of service for the target application. By consuming available heap memory, the attack forces the JVM to trigger excessive garbage collection cycles or causes an \u003ccode\u003eOutOfMemoryError\u003c/code\u003e, rendering the service unresponsive to legitimate users. Given the nature of WebSocket services, this disruption affects real-time communication channels and connected clients, potentially impacting broader infrastructure depending on the application's role.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch immediately by upgrading to a version of the MCP Kotlin SDK that enforces a mandatory \u003ccode\u003emaxFrameSize\u003c/code\u003e limit in the \u003ccode\u003eApplication.mcpWebSocket\u003c/code\u003e configuration.\u003c/li\u003e\n\u003cli\u003eImplement global memory monitoring and alerting for JVM heap usage to detect rapid, anomalous memory spikes that precede a crash.\u003c/li\u003e\n\u003cli\u003eReview existing Ktor WebSocket configurations in all applications using the MCP Kotlin SDK to ensure \u003ccode\u003emaxFrameSize\u003c/code\u003e and \u003ccode\u003emaxFrameSize\u003c/code\u003e are explicitly constrained to reasonable bounds appropriate for the application traffic.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-11T14:01:13Z","date_published":"2026-10-11T14:01:13Z","id":"https://feed.craftedsignal.io/briefs/2026-10-mcp-kotlin-sdk-dos/","summary":"The MCP Kotlin SDK through version 0.15.0 is vulnerable to denial of service due to the absence of a maxFrameSize limit in the Ktor WebSocket configuration, allowing remote clients to trigger heap exhaustion.","title":"Denial of Service via Uncontrolled Memory Allocation in MCP Kotlin SDK","url":"https://feed.craftedsignal.io/briefs/2026-10-mcp-kotlin-sdk-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:model_context_protocol:mcp_kotlin_sdk:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}