Impact
The MCP Kotlin SDK through 0.15.0 contains an uncontrolled memory allocation flaw that allows a remote client to exhaust server memory. By abusing Ktor WebSockets installed without a maxFrameSize limit, an attacker can send narrow frame headers that claim payload sizes close to 2 GiB across one or a few connections, forcing the server to allocate large heap blocks and ultimately crash or become unresponsive.
Affected Systems
The affected product is the ModelContext Protocol Kotlin SDK up to and including version 0.15.0. Any installation that loads the SDK and exposes WebSocket endpoints via the Application.mcpWebSocket interface is vulnerable.
Risk and Exploitability
The severity is high, with a CVSS score of 8.7, and the exploit is possible over the network without authentication. Although EPSS data is not available and the vulnerability is not yet listed in the CISA KEV catalog, the lack of a frame size constraint makes the threat realistic for any exposed service.
OpenCVE Enrichment