Aias00 opened a new issue, #6644:
URL: https://github.com/apache/shenyu/issues/6644

   - severity: High
   - files: 
`shenyu-plugin/shenyu-plugin-mcp-server/src/main/java/org/apache/shenyu/plugin/mcp/server/transport/ShenyuStreamableHttpServerTransportProvider.java:461-490`
   - description: When a client sends a request with a `sessionId` that does 
not exist (server restart, timeout, stale client), `createSessionAndRestoreId` 
creates a new `McpServerSession`+`StreamableHttpSessionTransport`, stores them 
in `sessions`/`sessionTransports`, and processes one request — but, unlike 
`createTemporarySessionAndProcess` (which has a 
`.doFinally(...removeSession...)`), the restore path has no cleanup hook. The 
session and transport remain in both maps forever.
   - impact: Unbounded memory growth of 
`sessions`/`sessionTransports`/`ShenyuMcpExchangeHolder` via the stale-session 
restore path.
   - suggested_fix: Add a `doFinally` to `createSessionAndRestoreId` that calls 
`removeSession(actualSessionId)` and 
`ShenyuMcpExchangeHolder.remove(actualSessionId)`.
   - confidence: High
   - related_existing: none — #6473/#6117 are different defects.
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/00-consolidated-critical-high.md`](docs/scan2-2026-08-02/00-consolidated-critical-high.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to