A Docker healthcheck was leaking memory on most of my MCP servers, and every one of them reported healthy the whole time.

The healthcheck hit /mcp every 30 seconds to prove the server was up. Each probe opened a new MCP transport session that nothing ever closed. I measured it on a live container today. Ten probes made ten sessions at about 37.6 KB each. Probing a dedicated /health route instead, 25 probes made zero.

My shared MCP core library exists because of this exact leak. The audit showed its fix had reached 3 of my 16 servers. The other 11 were each piling up roughly 2,880 orphaned sessions a day, and a leaking server passes a healthcheck fine.

Chasing it turned up a bug in the Python MCP SDK too. Ending a session politely with a DELETE skips the step that removes it from the server's registry, so the dead session stays there for good. With an idle timeout set, a client that walks away without saying goodbye gets cleaned up and the polite one never does. A contributor split my comment out into its own issue this week and credited the finding to me.