GHSA-9pj6-vhgr-3mwh: RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service
- Identifiers
- CVE-2026-63128GHSA-9pj6-vhgr-3mwh
- Published
- Record updated
- Affected
- rmcp < 2.0.0
- Fixed in
- 2.0.0
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.6%
Summary
Unauthenticated remote attackers can leak one entry from the in-memory session table of `LocalSessionManager` per HTTP request by sending a well-formed JSON-RPC `POST` that is not an `InitializeRequest` to the rmcp Streamable HTTP server. `handle_post` in `crates/rmcp/src/transport/streamable_http_server/tower.rs` allocates the session before validating the body and early-returns on failure without calling `close_session`, so the leak is permanent for the process lifetime. The source reports over 2,000 leaking requests per second from a single Python client, equivalent to roughly 75 GB of resident memory per day.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- rmcpcrates.ioLLM dependency since 2025-03-16
Related items
- HighHermes Agent - Pre-Authentication Disk ConsumptionSimilar attack · Tenable Research Advisories
- MediumHermes Agent - Pre-Authentication Memory ExhaustionSimilar attack · Tenable Research Advisories
- MediumGHSA-v36g-jcw9-x7cw: Pydantic AI: Excessive resource use when local web fetching converts nested HTMLSimilar attack · GitHub Advisory Database
- MediumGHSA-v2xh-2vp8-57h8: Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrlSimilar attack · GitHub Advisory Database
- MediumGHSA-fpf4-vwcp-v4hp: Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`Similar attack · GitHub Advisory Database