CVE-2026-40608: Unbounded request body crashes Next AI Draw.io MCP sidecar
Next AI Draw.io versions prior to 0.4.15 accumulated entire HTTP request bodies into memory in three POST handlers (/api/state, /api/restore, /api/history-svg) of its embedded sidecar, so a large payload (e.g. 500 MiB) could exhaust the Node.js heap and crash the MCP server. The issue is fixed in version 0.4.15.
Disclosed 21 April 2026 · Record updated 13 September 2026
Impact
Out-of-memory denial of service crashing the MCP server hosting the AI diagram integration.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-40608
