← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 25, 2026 · 20:36via CVEFeed

CVE-2026-53965 - MCP PHP SDK: Unbounded SSE buffer in HttpTransport enables client-side denial of service

Brief

CVE ID : CVE-2026-53965

Published : Aug. 25, 2026, 8:36 p. m.

  • 35 minutes ago

Description : The MCP PHP SDK (Composer package mcp/sdk) is the official Model Context Protocol SDK for PHP. In versions 0.

  • 0 through 0.
  • 0, the HTTP client transport reads a Server-Sent Events response stream incrementally and appends each chunk to an in-memory buffer with no upper bound.

The buffer is only flushed when an SSE event delimiter, a double newline, is found, so a remote MCP server that streams response bytes without ever sending the delimiter causes the buffer to grow without limit.

A malicious, compromised, or man-in-the-middle-controlled server that the client connects to over the HTTP transport can exploit this to exhaust the client process's memory, triggering a fatal allocation error or OS out-of-memory kill and denying service to the MCP client.

Read more on CVEFeed