Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

MCP PHP SDK Memory Exhaustion Vulnerability

The MCP PHP SDK versions 0.5.0 through 0.7.0 are vulnerable to memory exhaustion when the HTTP client transport connects to a malicious or compromised server that streams data without sending SSE event delimiters, causing unbounded buffer growth and denial of service.

Disclosed 25 August 2026 · Record updated 13 September 2026

Impact

Remote denial of service against MCP PHP SDK clients connecting to untrusted server endpoints via HTTP transport without requiring authentication or user interaction.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-53965