PT-2026-93789 · Crates.Io · Rmcp

CVE-2026-63128

·

Published

2026-09-16

·

Updated

2026-09-22

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions rmcp versions prior to 2.0.0
Description The stateful Streamable HTTP server in the rmcp crate contains a memory leak that can lead to a Denial of Service. An unauthenticated remote attacker can exploit this by sending a well-formed JSON-RPC POST request that is either not an initialization request or is an initialization request with a mismatched protocol header.
The issue occurs in the StreamableHttpService::handle post() function, which calls LocalSessionManager.create session() to allocate a session before validating the request body. If validation fails, the server returns an error without removing the LocalSessionHandle from the LocalSessionManager.sessions table. This results in the permanent retention of session and channel state for the lifetime of the server process.
Repeated requests can cause the shared session table to grow without bound, leading to increased latency for legitimate clients due to lock contention on the RwLock and eventual memory exhaustion, which can terminate the server. In a verified scenario, a single client could leak approximately 170 million entries per day, consuming roughly 75 GB of resident memory.
Recommendations Update to version 2.0.0. As a temporary mitigation, restrict network access to the Streamable HTTP server to trusted sources only to prevent unauthenticated remote attackers from sending malicious requests.

Exploit

Fix

Missing Release of Resource after Effective Lifetime

Resource Exhaustion

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63128
GHSA-9PJ6-VHGR-3MWH
OPENSUSE-SU-2026:11849-1

Affected Products

Rmcp