<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T15:12:39.830035+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-342751</id>
    <title>EUVD-2026-342751</title>
    <updated>2026-10-06T15:12:39.875861+00:00</updated>
    <content>EUVD-2026-342751</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-342751"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-67430</id>
    <title>fkie_cve-2026-67430</title>
    <updated>2026-10-06T15:12:39.875898+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not expire sessions by default, so repeated initialize requests retain unbounded ServerSession objects and can exhaust process memory. This issue is fixed in version 0.23.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-67430"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-52jp-gj8w-j6xh</id>
    <title>GHSA-52jp-gj8w-j6xh — MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood</title>
    <updated>2026-10-06T15:12:39.875932+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: mcp</p>
<p>## Summary</p>
<p>In its default configuration, `MCP::Server::Transports::StreamableHTTPTransport` never expires sessions. Every successful `initialize` request stores a new `ServerSession` and a session record under a fresh UUID, and the only path that removes them is an explicit client-issued HTTP `DELETE`. An unauthenticated attacker can repeatedly initialize new sessions and immediately disconnect, forcing the server to retain an unbounded number of `ServerSession` objects until memory is exhausted.</p>
<p>## Affected component</p>
<p>`lib/mcp/server/transports/streamable_http_transport.rb`:</p>
<p>- Line 27, constructor: `def initialize(server, stateless: false, enable_json_response: false, session_idle_timeout: nil)` — the default for `session_idle_timeout` is `nil`.
- Line 46: `start_reaper_thread if @session_idle_timeout` — when the timeout is `nil`, the reaper that prunes idle sessions is never started.
- Lines 604–643 (`handle_initialization`): every successful `initialize` inserts a new session record; the only removal sites are `handle_delete` (client-controlled) and stream-error paths.</p>
<p>The project README acknowledges the insecure default (line 1605):</p>
<p>&gt; By default, sessions do not expire. To mitigate session hijacking risks, you can set a `session_idle_timeout` (in seconds).</p>
<p>Per-session memory cost is non-trivial: each entry contains a `ServerSession` instance (with its own `Mutex`, `@in_flight` hash, capabilities hash, and server reference), a top-level hash entry under the session…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-52jp-gj8w-j6xh"/>
  </entry>
</feed>
