vciy

CVEs we hold for Modelcontextprotocol

Records whose assigning authority named Modelcontextprotocol as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-67432MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransportmodelcontextprotocol ruby-sdk
CVE-2026-67431MCP Ruby SDK: Ruby SSE Session Poisoningmodelcontextprotocol ruby-sdk
CVE-2026-67430MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize floodmodelcontextprotocol ruby-sdk
CVE-2026-64684RMCP: Custom HTTP headers leak to cross-origin redirect targetsmodelcontextprotocol rust-sdk
CVE-2026-63128RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote…modelcontextprotocol rust-sdk
CVE-2026-63127RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discoverymodelcontextprotocol rust-sdk
CVE-2026-63119MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)modelcontextprotocol ruby-sdk
CVE-2026-63118MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protectionmodelcontextprotocol ruby-sdk
CVE-2026-59950MCP Python SDK: WebSocket server transport does not support Host/Origin validationmodelcontextprotocol python-sdk
CVE-2026-53965MCP PHP SDK: Unbounded SSE buffer in HttpTransport enables client-side denial of servicemodelcontextprotocol php-sdk
CVE-2026-53937MCP Kotlin SDK's unbounded line buffer in StdioServerTransport/StdioClientTransport leads to memory exhaustion (DoS)modelcontextprotocol io.modelcontextprotocol:kotlin-sdk-serv…
CVE-2026-52870MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasksmodelcontextprotocol python-sdk
CVE-2026-52869MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principalmodelcontextprotocol python-sdk
CVE-2026-45781MCP Registry: OCI ownership validation fails open on upstream rate limits, allowing attacker-controlled package claimsmodelcontextprotocol registry
CVE-2026-44430MCP Registry: Unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses…modelcontextprotocol registry
CVE-2026-44429MCP Registry: Stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl`modelcontextprotocol registry
CVE-2026-44428MCP Registry: GitHub OIDC tokens replayable across registry deployments due to shared audiencemodelcontextprotocol registry
CVE-2026-44427MCP Registry: Open Redirectmodelcontextprotocol registry
CVE-2026-42559RMCP: DNS rebinding vulnerability in rmcp Streamable HTTP server transportmodelcontextprotocol rust-sdk
CVE-2026-35568MCP Java-SDK has a DNS Rebinding Vulnerabilitymodelcontextprotocol java-sdk
CVE-2026-34742Model Context Protocol Go SDK: DNS Rebinding Protection Disabled by Default for Servers Running on Localhostmodelcontextprotocol go-sdk
CVE-2026-34237MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)modelcontextprotocol java-sdk
CVE-2026-33946MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replaymodelcontextprotocol ruby-sdk
CVE-2026-33252MCP Go SDK Allows Cross-Site Tool Execution for HTTP Servers without Authorizatrionmodelcontextprotocol go-sdk
CVE-2026-27896MCP Go SDK Vulnerable to Improper Handling of Case Sensitivitymodelcontextprotocol go-sdk
CVE-2026-27735mcp-server-git : Path traversal in git_add allows staging files outside repository boundariesmodelcontextprotocol servers
CVE-2026-25536@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reusemodelcontextprotocol typescript-sdk
CVE-2025-68145mcp-server-git has missing path validation when using --repository flagmodelcontextprotocol servers
CVE-2025-68144mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local filesmodelcontextprotocol servers
CVE-2025-68143mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locationsmodelcontextprotocol servers
CVE-2025-66416DNS Rebinding Protection Disabled by Default in Model Context Protocol Python SDK for Servers Running on Localhostmodelcontextprotocol python-sdk
CVE-2025-66414DNS Rebinding Protection Disabled by Default in Model Context Protocol TypeScript SDK for Servers Running on Localhostmodelcontextprotocol typescript-sdk
CVE-2025-58444MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Servermodelcontextprotocol inspector
CVE-2025-53366MCP SDK Vulnerable to FastMCP Server Validation Error, Leading to Denial of Servicemodelcontextprotocol python-sdk
CVE-2025-53365MCP Python SDK has Unhandled Exception in Streamable HTTP Transport ,Leading to Denial of Servicemodelcontextprotocol python-sdk
CVE-2025-53110Model Context Protocol Servers Vulnerable to Path Validation Bypass via Colliding Path Prefixmodelcontextprotocol servers
CVE-2025-53109Model Context Protocol Servers Vulnerable to Path Validation Bypass via Prefix Matching and Symlink Handlingmodelcontextprotocol servers
CVE-2025-49596MCP Inspector proxy server lacks authentication between the Inspector client and proxymodelcontextprotocol inspector

38 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.