MCP PHP SDK Memory Exhaustion Vulnerability
The MCP PHP SDK versions 0.5.0 through 0.7.0 are vulnerable to memory exhaustion when the HTTP client transport connects to a malicious or compromised server that streams data without sending SSE event delimiters, causing unbounded buffer growth and denial of service.
Disclosed 25 August 2026 · Record updated 13 September 2026
Impact
Remote denial of service against MCP PHP SDK clients connecting to untrusted server endpoints via HTTP transport without requiring authentication or user interaction.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-53965
