modelcontextprotocol
AI / MLoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting modelcontextprotocol.
- CVE-2026-67432MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport7.5
- CVE-2026-63119MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)6.2
- CVE-2026-67430MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood5.3
- CVE-2026-59950MCP Python SDK: WebSocket server transport does not support Host/Origin validation8.1
- CVE-2026-52870MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks7.6
- CVE-2026-52869MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal7.1
- CVE-2026-44428MCP Registry: GitHub OIDC tokens replayable across registry deployments due to shared audience4.7
- CVE-2026-44429MCP Registry: Stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl`5.4
- CVE-2026-44430MCP Registry: Unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist4.0
- CVE-2026-45781MCP Registry: OCI ownership validation fails open on upstream rate limits, allowing attacker-controlled package claims3.5
- CVE-2026-42559RMCP: DNS rebinding vulnerability in rmcp Streamable HTTP server transport8.8
- CVE-2026-35568MCP Java-SDK has a DNS Rebinding Vulnerability5.7
- CVE-2026-34742Model Context Protocol Go SDK: DNS Rebinding Protection Disabled by Default for Servers Running on Localhost8.1
- CVE-2026-34237MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)6.1
- CVE-2026-33946MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay5.9