CVE-2026-67432 | modelcontextprotocol ruby-sdk up to 0.22.x StreamableHTTPTransport resource consumption (EUVD-2026-50502)

SecurityVulns

A vulnerability marked as problematic has been reported in modelcontextprotocol ruby-sdk up to 0.22.x. The affected element is the function MCP::Server::Transports::StreamableHTTPTransport of the component StreamableHTTPTransport. The manipulation leads to resource consumption.

This vulnerability is traded as CVE-2026-67432. It is possible to initiate the attack remotely. There is no exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More