Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

MCP Ruby SDK memory exhaustion via unbounded session objects

MCP Ruby SDK versions prior to 0.23.0 fail to expire sessions by default in StreamableHTTPTransport, allowing repeated initialize requests to create unbounded ServerSession objects and exhaust process memory.

Disclosed 29 July 2026 · Record updated 13 September 2026

Impact

Repeated initialize requests can exhaust process memory on affected servers

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-67430