Junglewise Threat Intelligence

CVE-2026-39313: MCP-Framework: Unbounded memory allocation in readRequestBody allows denial of service via HTTP transport

CVE-2026-39313 · Severity: high · CVSS 4 · Published 2026-04-16

Vendors: npm.

Executive brief

MCP-Framework is a TypeScript framework for building Model Context Protocol servers, used by applications to handle HTTP requests. A vulnerability in the HTTP request handling allows anyone on the network to crash servers running MCP-Framework by sending a specially crafted large POST request. No username or password is needed to exploit this, and a single request can consume all available memory and bring down the service, impacting availability and user operations.

Technical details

The vulnerability is an unbounded memory allocation issue (CWE-770) in the readRequestBody() function in src/transports/http/server.ts (lines 224-240). The function concatenates HTTP request body chunks into a string without size validation, despite a maxMessageSize configuration value (4MB default) being defined in DEFAULT_HTTP_STREAM_CONFIG. The function executes before any authentication checks, making it accessible to unauthenticated remote attackers over the network. An attacker can send a 50MB+ HTTP POST request to trigger exponential memory growth and server crash. The function offers no attack preconditions: no authentication is required, no user interaction needed, and the service is network-reachable by default. The fix, committed to the repository, enforces size checking during chunk accumulation and destroys the request if limits are exceeded.

Affected products

  • QuantGeekDev mcp-framework <= 0.2.21

Timeline

  • 2026-04-16: disclosed: Vulnerability published as GHSA-353c-v8x9-v7c3 and CVE-2026-39313
  • 2026-04-16: patched: Fix committed enforcing maxMessageSize in readRequestBody()

References