All 6 CVE vulnerabilities found in ruby-sdk, with AI-generated Chinese analysis, references, and POCs.
Vendor: modelcontextprotocol
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-67432 | MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport CWE-770 | 7.5 | High | 2026-07-29 |
| CVE-2026-67431 | MCP Ruby SDK: Ruby SSE Session Poisoning CWE-284 | 8.3 | High | 2026-07-29 |
| CVE-2026-63119 | MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS) CWE-400 | 6.2 | Medium | 2026-07-29 |
| CVE-2026-67430 | MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood CWE-401 | 5.3 | Medium | 2026-07-29 |
| CVE-2026-63118 | MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection CWE-346 | 6.9 | Medium | 2026-07-29 |
| CVE-2026-33946 | MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay CWE-384 | 8.2 | - | 2026-03-27 |
All 6 known CVE vulnerabilities affecting ruby-sdk with full Chinese analysis, references, and POCs where available.