Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-39313: unbounded request body in mcp-framework enables remote DoS

In mcp-framework 0.2.21 and below, the HTTP transport's readRequestBody() concatenates request body chunks without enforcing the maxMessageSize setting, letting a remote unauthenticated attacker crash any mcp-framework HTTP server with a single large POST to /mcp via memory exhaustion. The issue was fixed in version 0.2.22.

Disclosed 16 April 2026 · Record updated 13 September 2026

Impact

Remote unauthenticated attackers can cause memory exhaustion and denial of service on any MCP server built on affected versions of mcp-framework.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-39313