Incident database
RMCP Unauthenticated Session-Table Leak DoS (CVE-2026-63128)
An unauthenticated attacker can leak session entries from rmcp's HTTP server by sending malformed JSON-RPC requests, causing permanent memory allocation that eventually exhausts server memory at a rate of ~75 GB per day.
Disclosed 16 September 2026 · Record updated 17 September 2026
Impact
Remote denial-of-service through uncontrolled memory exhaustion; verified at 2000+ leak requests per second translating to 170 million leaked entries and 75 GB of memory consumption daily.
Our coverage
VulnerabilitiesA GitHub advisory published on 16 September 2026 says unauthenticated requests to rmcp's Streamable HTTP transport leak session entries at roughly 75GB of memory a day.
17 Sept 2026
Sources
- github.comhttps://github.com/advisories/GHSA-9pj6-vhgr-3mwh