Description
MCP Kotlin SDK through 0.15.0 contains an uncontrolled memory allocation vulnerability that allows remote clients to exhaust server memory because Application.mcpWebSocket installs Ktor WebSockets without a maxFrameSize limit. Attackers can send small frame headers declaring payloads near 2 GiB over one or a few connections, forcing huge heap allocations and causing denial of service.
Published: 2026-10-11
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service via Memory Exhaustion
Action: Immediate Patch
AI Analysis

Impact

The MCP Kotlin SDK through 0.15.0 contains an uncontrolled memory allocation flaw that allows a remote client to exhaust server memory. By abusing Ktor WebSockets installed without a maxFrameSize limit, an attacker can send narrow frame headers that claim payload sizes close to 2 GiB across one or a few connections, forcing the server to allocate large heap blocks and ultimately crash or become unresponsive.

Affected Systems

The affected product is the ModelContext Protocol Kotlin SDK up to and including version 0.15.0. Any installation that loads the SDK and exposes WebSocket endpoints via the Application.mcpWebSocket interface is vulnerable.

Risk and Exploitability

The severity is high, with a CVSS score of 8.7, and the exploit is possible over the network without authentication. Although EPSS data is not available and the vulnerability is not yet listed in the CISA KEV catalog, the lack of a frame size constraint makes the threat realistic for any exposed service.

Generated by OpenCVE AI on October 11, 2026 at 13:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a recent version of the Kotlin SDK that implements a maximum WebSocket frame size limit
  • If upgrading is not possible immediately, configure the Ktor WebSocket maxFrameSize to a lower value such as 1 MiB to reduce the allocation footprint
  • Implement network controls or rate limiting to detect and restrict unusually large WebSocket frames from untrusted clients

Generated by OpenCVE AI on October 11, 2026 at 13:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description MCP Kotlin SDK through 0.15.0 contains an uncontrolled memory allocation vulnerability that allows remote clients to exhaust server memory because Application.mcpWebSocket installs Ktor WebSockets without a maxFrameSize limit. Attackers can send small frame headers declaring payloads near 2 GiB over one or a few connections, forcing huge heap allocations and causing denial of service.
Title MCP Kotlin SDK through 0.15.0 Memory Exhaustion via Application.mcpWebSocket
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:27.291Z

Reserved: 2026-10-11T01:51:48.616Z

Link: CVE-2026-108714

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:14.430

Modified: 2026-10-11T13:17:14.430

Link: CVE-2026-108714

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T13:30:19Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling