Vulnerabilidades em modelcontextprotocol

38 resultados
Análise Vexday

O Model Context Protocol apresenta 28 vulnerabilidades catalogadas, com 9 publicadas nos últimos 90 dias, indicando atividade de descoberta contínua. Nenhuma vulnerabilidade está sob ataque ativo no momento, mas a fraqueza dominante em path traversal (CWE-22) merece monitoramento, especialmente dado o volume recente de divulgações. O risco atual é moderado, com apenas 1 vulnerabilidade crítica na base.

CVE-2026-67430MEDIUMMCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize floodEPSS 0.3%CVE-2026-67431HIGHMCP Ruby SDK: Ruby SSE Session PoisoningEPSS 0.3%CVE-2026-27735MEDIUMmcp-server-git : Path traversal in git_add allows staging files outside repository boundariesEPSS 0.3%CVE-2026-44430MEDIUMMCP Registry: Unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlistEPSS 0.3%CVE-2026-25536HIGH@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuseEPSS 0.3%CVE-2026-27896HIGHMCP Go SDK Vulnerable to Improper Handling of Case SensitivityEPSS 0.3%CVE-2026-59950HIGHMCP Python SDK: WebSocket server transport does not support Host/Origin validationEPSS 0.2%CVE-2026-34237MEDIUMMCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)EPSS 0.2%CVE-2026-44428LOWMCP Registry: GitHub OIDC tokens replayable across registry deployments due to shared audienceEPSS 0.2%CVE-2026-42559HIGHRMCP: DNS rebinding vulnerability in rmcp Streamable HTTP server transportEPSS 0.2%CVE-2026-45781LOWMCP Registry: OCI ownership validation fails open on upstream rate limits, allowing attacker-controlled package claimsEPSS 0.2%CVE-2026-63127HIGHRMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata DiscoveryEPSS 0.2%CVE-2026-63118MEDIUMMCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protectionEPSS 0.2%CVE-2026-53937MEDIUMMCP Kotlin SDK's unbounded line buffer in StdioServerTransport/StdioClientTransport leads to memory exhaustion (DoS)EPSS 0.2%CVE-2026-33252HIGHMCP Go SDK Allows Cross-Site Tool Execution for HTTP Servers without AuthorizatrionEPSS 0.2%CVE-2026-44429MEDIUMMCP Registry: Stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl`EPSS 0.2%CVE-2026-35568HIGHMCP Java-SDK has a DNS Rebinding VulnerabilityEPSS 0.1%CVE-2026-63119MEDIUMMCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)EPSS 0.1%