<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:model_context_protocol:mcp_kotlin_sdk:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3amodel_context_protocolmcp_kotlin_sdk/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 11 Oct 2026 14:01:13 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3amodel_context_protocolmcp_kotlin_sdk/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Denial of Service via Uncontrolled Memory Allocation in MCP Kotlin SDK</title><link>https://feed.craftedsignal.io/briefs/2026-10-mcp-kotlin-sdk-dos/</link><pubDate>Sun, 11 Oct 2026 14:01:13 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-mcp-kotlin-sdk-dos/</guid><description>The MCP Kotlin SDK through version 0.15.0 is vulnerable to denial of service due to the absence of a maxFrameSize limit in the Ktor WebSocket configuration, allowing remote clients to trigger heap exhaustion.</description><content:encoded><![CDATA[<p>The MCP Kotlin SDK, specifically versions up to and including 0.15.0, contains an uncontrolled memory allocation vulnerability (CVE-2026-108714) within the <code>Application.mcpWebSocket</code> component. The vulnerability arises because the SDK initializes Ktor WebSockets without explicitly configuring a <code>maxFrameSize</code> limit. This oversight allows a remote attacker to send crafted WebSocket frame headers that declare very large payload sizes, approaching 2 GiB. By initiating one or a small number of concurrent connections and sending these malformed headers, an attacker can force the server to attempt massive heap allocations, leading to rapid memory exhaustion and a subsequent denial of service (DoS) state. This vulnerability impacts any service utilizing the affected SDK version for WebSocket communication, as the resource consumption occurs before the application logic processes the data.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in an immediate denial of service for the target application. By consuming available heap memory, the attack forces the JVM to trigger excessive garbage collection cycles or causes an <code>OutOfMemoryError</code>, rendering the service unresponsive to legitimate users. Given the nature of WebSocket services, this disruption affects real-time communication channels and connected clients, potentially impacting broader infrastructure depending on the application's role.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Patch immediately by upgrading to a version of the MCP Kotlin SDK that enforces a mandatory <code>maxFrameSize</code> limit in the <code>Application.mcpWebSocket</code> configuration.</li>
<li>Implement global memory monitoring and alerting for JVM heap usage to detect rapid, anomalous memory spikes that precede a crash.</li>
<li>Review existing Ktor WebSocket configurations in all applications using the MCP Kotlin SDK to ensure <code>maxFrameSize</code> and <code>maxFrameSize</code> are explicitly constrained to reasonable bounds appropriate for the application traffic.</li>
</ol>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category></item></channel></rss>