Impact
The vulnerability allows an unauthenticated attacker to send a request to the web_url_read endpoint with a URL that points to a server lacking a Content-Length header. The server then reads the entire response body into memory and processes it, bypassing the configured size limit and creating a scenario where memory or CPU resources can be exhausted. This results in denial of service. The weakness is represented by CWE-400.
Affected Systems
The issue affects the mcp-searxng Model Context Protocol server developed by ihor-sokoliuk. All versions prior to 1.7.1 are vulnerable. The vulnerable code resides in src/index.ts and src/url-reader.ts. Upgrading to v1.7.1 or newer removes the flaw.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, and the EPSS score is < 1%, indicating limited exploitation potential. The vulnerability can be exploited remotely over HTTP without authentication, making it readily actionable. An attacker can trigger memory exhaustion or CPU overload, causing the service to become unresponsive. Official remediation is available in the 1.7.1 release, and the vulnerability is not listed in CISA KEV.
OpenCVE Enrichment