<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Mcp-Go (&lt;= 1.2.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/mcp-go--1.2.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 11 Oct 2026 16:02:48 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/mcp-go--1.2.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Denial of Service Vulnerability in mcp-go</title><link>https://feed.craftedsignal.io/briefs/2026-10-mcp-go-dos/</link><pubDate>Sun, 11 Oct 2026 16:02:48 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-mcp-go-dos/</guid><description>mcp-go versions through 1.2.1 contain a denial of service vulnerability in StreamableHTTPServer.ServeHTTP that allows remote, unauthenticated attackers to trigger memory exhaustion via oversized POST request bodies.</description><content:encoded><![CDATA[<p>mcp-go versions through 1.2.1 are susceptible to a denial of service (DoS) vulnerability located within the StreamableHTTPServer.ServeHTTP function. The vulnerability is caused by an unsafe implementation where the server reads the entirety of an incoming POST request body into memory using the io.ReadAll function before any validation logic is executed. This design flaw allows remote, unauthenticated attackers to transmit either a single arbitrarily large POST body or multiple concurrent requests, rapidly consuming the available memory of the host process. Successful exploitation leads to memory exhaustion, causing the server process to crash or be terminated by the operating system's out-of-memory (OOM) killer. This impacts the availability of any service relying on the mcp-go library for handling HTTP streams.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability results in a denial of service for the affected application. Because the impact is memory exhaustion, the entire service process may terminate, requiring manual intervention or automated restart procedures to recover. This affects any infrastructure or internal service components that have integrated mcp-go versions 1.2.1 or earlier for handling HTTP communication.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the mcp-go library to a version later than 1.2.1 where request body validation occurs prior to buffering or where memory limits are enforced during read operations.</li>
<li>Implement request body size limits at the load balancer or reverse proxy layer (e.g., Nginx client_max_body_size) to prevent excessively large payloads from reaching the application server.</li>
<li>Audit custom HTTP server implementations using mcp-go to ensure that io.ReadAll is not used on unvalidated request streams.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category></item></channel></rss>