Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
Vulnerability Description
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem reads and parses an entire JSON-RPC POST body without a size limit, allowing an unauthenticated remote attacker to exhaust process memory. This issue is fixed in version 0.23.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
不加限制或调节的资源分配
Vulnerability Title
Model Context Protocol MCP Ruby SDK 资源管理错误漏洞
Vulnerability Description
Model Context Protocol MCP Ruby SDK是Model Context Protocol组织的一个Ruby软件开发工具包组件。 Model Context Protocol MCP Ruby SDK 0.23.0之前版本存在资源管理错误漏洞,该漏洞源于读取和解析JSON-RPC POST正文时未设置大小限制,允许未经身份验证的远程攻击者耗尽进程内存。
CVSS Information
N/A
Vulnerability Type
N/A