VulnWatch VulnWatch
← Back to dashboard
Medium github · GHSA-7683-3w9x-ch42

MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)

Published Jul 30, 2026 CVSS 6.2

Summary

The stdio transports in MCP::Server::Transports::StdioTransport and MCP::Client::Stdio read newline-delimited JSON-RPC frames using IO#gets with no limit argument. CRuby's IO#gets with no limit reads from the current position until the next separator (\n) with no upper bound on the returned string length. A peer that streams bytes without ever emitting a newline causes gets to accumulate the entire stream in a single Ruby String until the process is killed by the operating-system OOM killer.

This is the same vulnerability class tracked in sibling MCP SDKs as GHSA-74gp-qhv5-v493 (Kotlin), GHSA-wqgc-pwpr-pq7r (TypeScript), GHSA-655q-2283-6jgj (Python), and others. It was identified during a cross-SDK audit; ruby-sdk had no prior report.

Affected code

Verified at main @ cf44475c.

Server transport — lib/mcp/server/transports/stdio_transport.rb

# line 23
while @open && (line = $stdin.gets)        #

Affected AI Products

mcp server
Get the weekly digest. Every Monday: top AI security stories of the week. Free.