Skip to content

Unbounded reads when parsing Server-Sent Events in HTTP client transports

Moderate
Kehrlann published GHSA-5q7x-232h-f834 Aug 19, 2026

Package

maven io.modelcontextprotocol.sdk:mcp-core (Maven)

Affected versions

>= 0.18.0, < 0.18.4
>= 1.0.0, < 1.1.4
2.0.0

Patched versions

0.18.4
1.1.4
2.0.1

Description

Summary

The MCP Java SDK's HTTP client transports (HttpClientStreamableHttpTransport and HttpClientSseClientTransport) both parse Server-Sent Events through a shared subscriber, ResponseSubscribers.SseLineSubscriber. It accumulates every data: line into an unbounded StringBuilder and only flushes/dispatches the event on a blank line. A malicious or compromised MCP HTTP server can send an endless stream of data: lines without ever emitting the blank-line SSE terminator, causing unbounded heap growth in the client process until OOM or severe GC pressure.

Am I affected?

If your application uses HttpClientStreamableHttpTransport or HttpClientSseClientTransport (i.e. McpClient configured with the Streamable HTTP or SSE HTTP client transport) to connect to an MCP server that is untrusted, or reachable over a network path where responses can be tampered with.

Details

Multi-line data: fields are valid per the SSE spec and are intentionally concatenated before dispatch; the issue is the absence of any maximum event size or maximum line count. There is no analogue anywhere in this SDK of a frame-size cap (e.g. nothing resembling ReadBuffer.DEFAULT_MAX_FRAME_SIZE in other SDKs) applied to this buffer.

It affects both the long-lived GET event stream and the inline SSE returned on a POST response, since both paths funnel through the same subscriber.

Impact

Client-side denial-of-service (CWE-400 / CWE-770): unbounded memory use in the MCP client process until OOM or severe GC, with little CPU cost to the attacker. Any Java application using HttpClientStreamableHttpTransport or HttpClientSseClientTransport against an untrusted MCP server (or over HTTP that can be tampered with) is affected. There is no remote code execution and no direct compromise of the server.

Weaknesses

  • CWE-400: Uncontrolled Resource Consumption
  • CWE-770: Allocation of Resources Without Limits or Throttling

Mitigation

Upgrade to 0.18.4, 1.1.4 or 2.0.1

Severity

Moderate

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE ID

No known CVE

Weaknesses

Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated. Learn more on MITRE.