
Found an unbounded HTTP body vulnerability in next-ai-drawio’s MCP server. By sending a large POST payload, the server could exhaust memory and crash (OOM). Reported it, and it’s now fixed. CVE-2026-40608 assigned. Big thanks to the maintainers for the super-fast response Advisory: https://github.com/DayuanJiang/next-ai-draw-io/security/advisories/GHSA-9q7h-wgfw-p378
Post summary
The author discovered an OOM vulnerability in next-ai-drawio’s MCP server, reported it, and the issue has been fixed as documented in a GitHub advisory.

