Product
mcp-go versions through 1.2.1 contain a denial of service vulnerability in StreamableHTTPServer.ServeHTTP that allows remote, unauthenticated attackers to trigger memory exhaustion via oversized POST request bodies.