Mcp toolbox for databases
This hub aggregates every CVE we track for Mcp toolbox for databases, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.
12
CVEs tracked
4
Critical
5
High
0
In CISA KEV
Severity distribution
HIGH5CRITICAL4MEDIUM1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
5
6
0
0
2024-102026-09
Latest CVEs
The 12 most recently published vulnerabilities affecting Mcp toolbox for databases.
- CVE-2026-14541Authentication Bypass and Audience Confusion in MCP Toolbox OAuth Provider7.5
- CVE-2026-14540Server-Side Request Forgery via Unrestricted HTTP Redirection in MCP Toolbox6.1
- CVE-2026-14539Denial of Service via Unrestricted Payload Buffering in MCP Toolbox7.5
- CVE-2026-14538BigQuery Dataset Allowlist Bypass via Metadata Dry-Run in MCP Toolbox7.7
- CVE-2026-14537Authorization Bypass in MCP Toolbox Legacy HTTP Endpoints9.8
- CVE-2026-15829SQL Injection and Security Boundary Bypass in googleapis/mcp-toolbox8.1
- CVE-2026-11720Path Traversal in googleapis/mcp-toolbox HTTP Tool URL Builder9.1
- CVE-2026-11719An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement across older protocol handlers. While the 2025-11-25 protocol version handl...8.1
- CVE-2026-11718An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When the toolbox validates an opaque token via an OAuth 2...9.1
- CVE-2026-11717An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When verifying an unparsed opaque token via an OAuth 2.0 ...9.1
- CVE-2026-11624The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding attacks. Prior to the v0.25.0 release, users ...
- CVE-2026-9739Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `allowed-hosts` flags to align with MCP security guidelines. How...
Product normalization is registry-driven with AI assist and human review. How it works