modelcontextprotocol
AI / MLoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting modelcontextprotocol.
- CVE-2026-64684RMCP: Custom HTTP headers leak to cross-origin redirect targets6.8
- CVE-2026-63127RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery8.2
- CVE-2026-63128RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service7.5
- CVE-2026-53937MCP Kotlin SDK's unbounded line buffer in StdioServerTransport/StdioClientTransport leads to memory exhaustion (DoS)6.2
- CVE-2026-53965MCP PHP SDK: Unbounded SSE buffer in HttpTransport enables client-side denial of service
- CVE-2026-67432MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport7.5
- CVE-2026-67431MCP Ruby SDK: Ruby SSE Session Poisoning
- CVE-2026-63119MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)6.2
- CVE-2026-67430MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood5.3
- CVE-2026-63118MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
- CVE-2026-59950MCP Python SDK: WebSocket server transport does not support Host/Origin validation8.1
- CVE-2026-52870MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks7.6
- CVE-2026-52869MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal7.1
- CVE-2026-44428MCP Registry: GitHub OIDC tokens replayable across registry deployments due to shared audience4.7
- CVE-2026-44427MCP Registry: Open Redirect