Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/googleapis/mcp-toolbox/pull/3216 |
|
Sun, 02 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google mcp-toolbox |
|
| Vendors & Products |
Google
Google mcp-toolbox |
Fri, 31 Jul 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Jul 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows an unauthenticated attacker to cause a denial of service (DoS). The /mcp endpoint handler reads incoming payloads directly into system memory using an unrestricted buffer loop (io.ReadAll) without applying defensive constraints such as http.MaxBytesReader or pre-read Content-Length enforcement. By submitting a single, massive HTTP request body, an attacker can linearly consume available host memory until the runtime process is terminated by an Out-Of-Memory (OOM) error. | |
| Title | Denial of Service via Unrestricted Payload Buffering in MCP Toolbox | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2026-07-31T16:11:48.201Z
Reserved: 2026-07-03T02:17:44.796Z
Link: CVE-2026-14539
Updated: 2026-07-31T16:11:37.832Z
Status : Analyzed
Published: 2026-07-31T02:16:28.920
Modified: 2026-08-08T00:20:12.293
Link: CVE-2026-14539
No data.
OpenCVE Enrichment
Updated: 2026-08-03T10:30:18Z