Mcp toolbox for databases (googleapis/mcp-toolbox)
This hub aggregates every CVE we track for Mcp toolbox for databases (googleapis/mcp-toolbox), a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.
6
CVEs tracked
3
Critical
2
High
0
In CISA KEV
Severity distribution
CRITICAL3HIGH2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
4
2
0
0
2024-102026-09
Latest CVEs
The 6 most recently published vulnerabilities affecting Mcp toolbox for databases (googleapis/mcp-toolbox).
- CVE-2026-16481Server-Side Request Forgery (SSRF) and Credential Exfiltration in googleapis/mcp-toolbox cloud-healthcare-fhir-fetch-page Tool
- CVE-2026-15829SQL Injection and Security Boundary Bypass in googleapis/mcp-toolbox8.1
- CVE-2026-11720Path Traversal in googleapis/mcp-toolbox HTTP Tool URL Builder9.1
- CVE-2026-11719An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement across older protocol handlers. While the 2025-11-25 protocol version handl...8.1
- CVE-2026-11718An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When the toolbox validates an opaque token via an OAuth 2...9.1
- CVE-2026-11717An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When verifying an unparsed opaque token via an OAuth 2.0 ...9.1
Product normalization is registry-driven with AI assist and human review. How it works