Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-52jp-gj8w-j6xh | MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood |
Thu, 30 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Jul 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Modelcontextprotocol
Modelcontextprotocol ruby-sdk |
|
| Vendors & Products |
Modelcontextprotocol
Modelcontextprotocol ruby-sdk |
Wed, 29 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not expire sessions by default, so repeated initialize requests retain unbounded ServerSession objects and can exhaust process memory. This issue is fixed in version 0.23.0. | |
| Title | MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood | |
| Weaknesses | CWE-401 CWE-770 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-30T15:19:09.224Z
Reserved: 2026-07-29T15:07:24.991Z
Link: CVE-2026-67430
Updated: 2026-07-30T14:16:41.653Z
Status : Deferred
Published: 2026-07-29T20:17:11.960
Modified: 2026-07-30T19:30:33.710
Link: CVE-2026-67430
No data.
OpenCVE Enrichment
Updated: 2026-08-03T13:00:07Z
Github GHSA