Search
Find merged stories by title or summary.
cve-2026-53965
MCP PHP SDK: Unbounded SSE buffer in HttpTransport enables client-side denial of service
CVE-2026-53965 - MCP PHP SDK: Unbounded SSE buffer in HttpTransport enables client-side denial of service
CVE ID : CVE-2026-53965 Published : Aug. 25, 2026, 8:36 p. m. • 35 minutes ago Description : The MCP PHP SDK (Composer package mcp/sdk) is the official Model Context Protocol SDK for PHP. In versions 0. 5. 0 through 0. 7. 0, the HTTP client transport reads a Server-Sent Events response stream incrementally and appends each chunk to an in-memory buffer with no upper bound. The buffer is only flushed when an SSE event delimiter, a double newline, is found, so a remote MCP server that streams response bytes without ever sending the delimiter causes the buffer to grow without limit. A malicious, compromised, or man-in-the-middle-controlled server that the client connects to over the HTTP transport can exploit this to exhaust the client process's memory, triggering a fatal allocation error or OS out-of-memory kill and denying service to the MCP client.
You've reached the end of current stories for this search.
