Impact
The vulnerability arises because MKP's default HTTP endpoint allows unauthenticated requests to the get_resource tool, which accepts limitBytes and tailLines parameters for pod logs. The code parses these parameters as unbounded int64 values and copies the resulting log stream into an in‑memory buffer without an application‑side cap. As a consequence, a remote attacker who can reach the default port 8080 can request an arbitrarily large log segment and force the server to allocate several gigabytes of memory, ultimately exhausting process memory, terminating the MKP server, and causing a denial of service for the MCP service.
Affected Systems
StacklokLabs' MKP server version 0.4.0 and earlier are affected. The issue exists in the cmd/server/main.go module which exposes the default HTTP endpoint and in pkg/mcp/server.go that registers the unauthenticated get_resource tool. Upgrading to version 0.4.1 or later resolves the problem. The unbounded log read can be triggered only when the attacker can access the default port 8080 of the MCP service.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity impact. The EPSS score of less than 1 % suggests a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. An attacker who can reach the default port can send a single tools/call request containing large limitBytes and tailLines values. Because the request‑frequency limiter does not constrain per‑request volume, the attacker can repeat the attack without rate‑limiting penalties, leading to repeated memory exhaustion and service denial. The attack does not require authentication, making it effectively unauthenticated.
OpenCVE Enrichment
Github GHSA