GEM · JULY 2026 · EARLY WARNING

MCP Ruby SDK Vulnerability: Potential Memory Allocation Attack

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-H669-8M4G-R2HCSeverity: HIGH

An unauthenticated remote attacker reportedly can force any MCP Ruby SDK server using `MCP::Server::Transports::StreamableHTTPTransport` to allocate gigabytes of memory by sending a single oversized JSON-RPC POST.

What happened

According to the GitHub advisory GHSA-h669-8m4g-r2hc, the MCP Ruby SDK appears to have a vulnerability in its StreamableHTTPTransport component. This vulnerability may allow an unauthenticated remote attacker to cause uncontrolled memory allocation by sending an oversized JSON-RPC request. The severity of this issue is currently under investigation, but it is recommended to upgrade to a version of the MCP Ruby SDK that includes the fix for this vulnerability. For more details, consult the primary source at https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-h669-8m4g-r2hc.

To assess your exposure, check if your application uses the MCP Ruby SDK and specifically the `MCP::Server::Transports::StreamableHTTPTransport` component. If so, review the version of the SDK you are using against the fixed versions listed in the advisory. It is advisable to upgrade to a secure version as soon as possible to mitigate potential risks.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If mcp ruby sdk is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats