Skip to content
HighVulnerability

GHSA-9pj6-vhgr-3mwh: RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service

Published
Record updated
View JSON
Affected
  • rmcp < 2.0.0
Fixed in
2.0.0
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.6%

Summary

Unauthenticated remote attackers can leak one entry from the in-memory session table of `LocalSessionManager` per HTTP request by sending a well-formed JSON-RPC `POST` that is not an `InitializeRequest` to the rmcp Streamable HTTP server. `handle_post` in `crates/rmcp/src/transport/streamable_http_server/tower.rs` allocates the session before validating the body and early-returns on failure without calling `close_session`, so the leak is permanent for the process lifetime. The source reports over 2,000 leaking requests per second from a single Python client, equivalent to roughly 75 GB of resident memory per day.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.