Vulnerabilidad · Publicado 21/08/2026
El transporte HTTP del servidor MCP Streamable (variantes WebFlux y WebMvc) no limita la cantidad de sesiones que retiene y no requiere autenticación de clientes por defecto. Un atacante remoto puede acumular sesiones ilimitadas, agotando la memoria del servidor y causando Denegación de Servicio (DoS). Esta vulnerabilidad afecta infraestructuras altas en México y Latinoamérica que dependen de aplicaciones Spring Framework.
The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server to accumulate an unbounded number of sessions over time, gradually exhausting available memory and ultimately causing a Denial of Service that affects all legitimate clients. Affected versions: Spring AI: 2.0.0
Score: 7.5/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-770
Publicado en NIST NVD.