Vulnerabilities in modelcontextprotocol
33 resultsVexday analysis
O Model Context Protocol apresenta 28 vulnerabilidades catalogadas, com 9 publicadas nos últimos 90 dias, indicando atividade de descoberta contínua. Nenhuma vulnerabilidade está sob ataque ativo no momento, mas a fraqueza dominante em path traversal (CWE-22) merece monitoramento, especialmente dado o volume recente de divulgações. O risco atual é moderado, com apenas 1 vulnerabilidade crítica na base.
CVE-2026-25536HIGH@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuseEPSS 0.3%CVE-2026-27896HIGHMCP Go SDK Vulnerable to Improper Handling of Case SensitivityEPSS 0.3%CVE-2026-52870HIGHMCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasksEPSS 0.2%CVE-2026-34237MEDIUMMCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)EPSS 0.2%CVE-2026-44428LOWMCP Registry: GitHub OIDC tokens replayable across registry deployments due to shared audienceEPSS 0.2%CVE-2026-42559HIGHRMCP: DNS rebinding vulnerability in rmcp Streamable HTTP server transportEPSS 0.2%CVE-2026-45781LOWMCP Registry: OCI ownership validation fails open on upstream rate limits, allowing attacker-controlled package claimsEPSS 0.2%CVE-2026-63118MEDIUMMCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protectionEPSS 0.2%CVE-2026-33252HIGHMCP Go SDK Allows Cross-Site Tool Execution for HTTP Servers without AuthorizatrionEPSS 0.2%CVE-2026-44429MEDIUMMCP Registry: Stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl`EPSS 0.2%CVE-2026-59950HIGHMCP Python SDK: WebSocket server transport does not support Host/Origin validationEPSS 0.1%CVE-2026-35568HIGHMCP Java-SDK has a DNS Rebinding VulnerabilityEPSS 0.1%CVE-2026-63119MEDIUMMCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)EPSS 0.1%