Description
The MCP PHP SDK (Composer package mcp/sdk) is the official Model Context Protocol SDK for PHP. In versions 0.5.0 through 0.7.0, the HTTP client transport reads a Server-Sent Events response stream incrementally and appends each chunk to an in-memory buffer with no upper bound. The buffer is only flushed when an SSE event delimiter, a double newline, is found, so a remote MCP server that streams response bytes without ever sending the delimiter causes the buffer to grow without limit. A malicious, compromised, or man-in-the-middle-controlled server that the client connects to over the HTTP transport can exploit this to exhaust the client process's memory, triggering a fatal allocation error or OS out-of-memory kill and denying service to the MCP client. The issue affects any client using HttpTransport against an untrusted server endpoint and does not require authentication or user interaction beyond initiating the connection. This issue is fixed in version 0.7.1.
Published: 2026-08-25
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The MCP PHP SDK’s HttpTransport reads Server‑Sent Events streams into an unbounded in‑memory buffer. Because the buffer is only flushed when a double‑newline delimiter is received, a server that streams data continuously without sending the delimiter causes the buffer to grow without limit. This leads to exhaustion of the client process’s memory, resulting in a fatal allocation error or an OS or kernel memory kill, and effectively denies service to the MCP client. The flaw is a classic resource‑exhaustion weakness, corresponding to CWE‑400 and CWE‑770.

Affected Systems

The vulnerability afflicts Model Context Protocol PHP SDK (Composer package mcp/sdk) versions 0.5.0 through 0.7.0. Any client that uses HttpTransport to connect to an untrusted MCP server is susceptible.

Risk and Exploitability

The CVSS score of 6.9 classifies the issue as moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw by controlling the target MCP server or performing a man‑in‑the‑middle attack; no authentication or user interaction is required beyond initiating the HTTP connection. The attack vector is remote and relies solely on the network connection to the untrusted server.

Generated by OpenCVE AI on August 26, 2026 at 02:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch to version 0.7.1
  • Ensure that HttpTransport is only used to connect to trusted, authenticated MCP endpoints
  • Disable or restrict the use of HttpTransport in environments that cannot guarantee server integrity

Generated by OpenCVE AI on August 26, 2026 at 02:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-7m52-jw36-44r3 MCP PHP SDK: client HttpTransport SSE buffer (sseBuffer .= chunk) grows unbounded when server withholds the event delimiter
History

Tue, 25 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description The MCP PHP SDK (Composer package mcp/sdk) is the official Model Context Protocol SDK for PHP. In versions 0.5.0 through 0.7.0, the HTTP client transport reads a Server-Sent Events response stream incrementally and appends each chunk to an in-memory buffer with no upper bound. The buffer is only flushed when an SSE event delimiter, a double newline, is found, so a remote MCP server that streams response bytes without ever sending the delimiter causes the buffer to grow without limit. A malicious, compromised, or man-in-the-middle-controlled server that the client connects to over the HTTP transport can exploit this to exhaust the client process's memory, triggering a fatal allocation error or OS out-of-memory kill and denying service to the MCP client. The issue affects any client using HttpTransport against an untrusted server endpoint and does not require authentication or user interaction beyond initiating the connection. This issue is fixed in version 0.7.1.
Title MCP PHP SDK: Unbounded SSE buffer in HttpTransport enables client-side denial of service
Weaknesses CWE-400
CWE-770
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-25T20:36:55.186Z

Reserved: 2026-06-11T15:50:01.282Z

Link: CVE-2026-53965

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T21:17:01.597

Modified: 2026-08-25T21:17:01.597

Link: CVE-2026-53965

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T02:30:04Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-770

    Allocation of Resources Without Limits or Throttling