CVE-2026-39313: unbounded request body in mcp-framework enables remote DoS
In mcp-framework 0.2.21 and below, the HTTP transport's readRequestBody() concatenates request body chunks without enforcing the maxMessageSize setting, letting a remote unauthenticated attacker crash any mcp-framework HTTP server with a single large POST to /mcp via memory exhaustion. The issue was fixed in version 0.2.22.
Disclosed 16 April 2026 · Record updated 13 September 2026
Impact
Remote unauthenticated attackers can cause memory exhaustion and denial of service on any MCP server built on affected versions of mcp-framework.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-39313
