{"data":{"id":"3e4e55cc-60f0-4af6-ac55-5929ba3ce17f","title":"GHSA-9pj6-vhgr-3mwh: RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service","summary":"Unauthenticated remote attackers can leak one entry from the in-memory session table of `LocalSessionManager` per HTTP request by sending a well-formed JSON-RPC `POST` that is not an `InitializeRequest` to the rmcp Streamable HTTP server. `handle_post` in `crates/rmcp/src/transport/streamable_http_server/tower.rs` allocates the session before validating the body and early-returns on failure without calling `close_session`, so the leak is permanent for the process lifetime. The source reports over 2,000 leaking requests per second from a single Python client, equivalent to roughly 75 GB of resident memory per day.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-9pj6-vhgr-3mwh","publishedAt":"2026-09-16T22:13:34.000Z","cveId":"CVE-2026-63128","cweIds":["CWE-400","CWE-401","CWE-772"],"cvssScore":"7.5","cvssSeverity":"high","severity":"high","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":["rmcp@< 2.0.0 (fixed: 2.0.0)"],"affectedPackageNames":["rmcp"],"affectedPackageRefs":["cargo:rmcp"],"affectedVendors":[],"affectedVendorsRaw":["RMCP","rmcp","MCP Streamable HTTP server transport"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.0063,"epssCheckedAt":"2026-10-10T04:57:26.392Z","kevDateAdded":null,"advisoryAliases":["GHSA-9pj6-vhgr-3mwh"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-09-16T22:13:34.000Z","capecIds":["CAPEC-125","CAPEC-130"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}