Saturday, 19 September 2026
0 agent hacks today 8 vs yesterday (8)

RMCP Unauthenticated Session-Table Leak DoS (CVE-2026-63128)

An unauthenticated attacker can leak session entries from rmcp's HTTP server by sending malformed JSON-RPC requests, causing permanent memory allocation that eventually exhausts server memory at a rate of ~75 GB per day.

Disclosed 16 September 2026 · Record updated 17 September 2026

Impact

Remote denial-of-service through uncontrolled memory exhaustion; verified at 2000+ leak requests per second translating to 170 million leaked entries and 75 GB of memory consumption daily.

Our coverage

Sources

  1. github.comhttps://github.com/advisories/GHSA-9pj6-vhgr-3mwh