What is CVE-2026-14539?
CVE-2026-14539 is an allocation of resources without limits vulnerability in the HTTP handler of Google mcp-toolbox up to version 1.4.0. It allows an unauthenticated attacker to cause a denial of service (DoS) by sending payloads to the /mcp endpoint that exhaust system memory. Affected users should upgrade to the latest version immediately.
Azərbaycanca: CVE-2026-14539 Google mcp-toolbox 1.4.0 və əvvəlki versiyalarında HTTP handler-də limitsiz resurs bölgüsü zəifliyidir. Bu, autentifikasiya olunmamış hücumçunun /mcp endpoint-ə yönləndirilmiş sorğular vasitəsilə sistem yaddaşını dolduraraq denial of service (DoS) yaratmağa imkan verir. Təsirə məruz qalan istifadəçilər dərhal ən son versiyaya yeniləmə aparmalıdırlar.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Google
FAQ2
What can an attacker achieve by exploiting CVE-2026-14539?
An unauthenticated attacker can cause a denial of service (DoS) by sending payloads to the /mcp endpoint that exhaust system memory due to the allocation of resources without limits.
What should affected users do to mitigate CVE-2026-14539?
Affected users should immediately upgrade to the latest version of Google mcp-toolbox.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.