Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-63119

Опубликовано: 29 июл. 2026
Источник: nvd
CVSS3: 6.2
EPSS Низкий

Описание

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StdioTransport and MCP::Client::Stdio in the mcp gem use IO#gets without a byte limit, allowing a peer that sends data without a newline to exhaust process memory. This issue is fixed in version 0.23.0.

EPSS

Процентиль: 3%
0.00129
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 6.2
github
12 дней назад

MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)

EPSS

Процентиль: 3%
0.00129
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-400