Impact
The MCP Kotlin SDK contains an unbounded line buffer in its stdio transport modules. The ReadBuffer.append routine records every incoming byte sequence into an internal Kotlinx.io.Buffer without any size restriction, only discarding data when a newline character is encountered. An attacker can therefore stream bytes without ever sending a newline, causing the buffer to grow indefinitely until the process runs out of memory and is terminated. This flaw is classified as Resource Exhaustion (CWE-400) and Uncontrolled Memory Allocation (CWE-770).
Affected Systems
The vulnerability affects the MCP Kotlin SDK suite, including the core, client, server, and primary SDK components from modelcontextprotocol:io.modelcontextprotocol. Any installation of versions 0.7.0 through 0.12.0 is susceptible, while 0.13.0 and later contain the fix.
Risk and Exploitability
With a CVSS score of 6.2 the severity is moderate, and the EPSS score is not available, suggesting no quantified probability yet. The flaw is not listed in the CISA KEV catalog. Attacks require only an untrusted source feeding data into the stdio stdin of a running MCP Kotlin SDK process; no special privileges are required. Once the vulnerable transport is triggered, an attacker can cause the host JVM or surrounding process to be OOM‑killed, effectively denying service to legitimate users.
OpenCVE Enrichment