Impact
The vulnerability resides in the rust-sdk's rmcp crate, which processes JSON‑RPC POST requests in a stateful Streamable HTTP server. An unauthenticated client can send a specially crafted request that triggers session creation before the message is fully validated. When validation fails early, the server does not remove the partially created session from the manager, permanently retaining its handle. Over time, repeated exploitation consumes memory, increases lock contention, slows legitimate traffic, and can eventually cause the server to terminate.
Affected Systems
Affected systems are implementations of the Model Context Protocol Rust SDK that use the rmcp crate prior to release 2.0.0, particularly those that expose the Streamable HTTP server endpoint. Applications built on modelcontextprotocol:rust-sdk that depend on older crate versions are directly impacted.
Risk and Exploitability
The CVSS score of 7.5 classifies this as a high severity remote denial‑of‑service. The EPSS score is below 1 %, indicating that real‑world exploitation is currently unlikely, and it is not listed in CISA’s KEV catalog. Nonetheless, the attack requires only network access to the HTTP service and no authentication, making the exploit straightforward to execute and capable of degrading or halting service availability.
OpenCVE Enrichment
Github GHSA