mcp-core is vulnerable to Denial of Service (DoS)
65
Medium Risk
The HTTP client transports parse Server-Sent Events through a shared component that accumulates every data: line into an unbounded StringBuilder and only flushes the event on a blank line. A connected server that sends endless data lines without the SSE terminator causes unbounded heap growth in the client process, leading to OutOfMemoryError or severe garbage-collection pressure. The fix caps SSE line and event sizes and bounds the HTTP response body read on the client transports.
You are affected if you are using a version that falls within the vulnerable range and you use the HTTP client transports to connect to an untrusted MCP server.
mcp-core is vulnerable to Denial of Service (DoS) in versions 0.18.0 - 0.18.3, 1.0.0 - 1.1.3 and 2.0.0 - 2.0.0.
Upgrade the mcp-core and/or the io.modelcontextprotocol.sdk:mcp-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant