CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-104120 MEDIUM

modelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server.py fetch_url server-side request forgery

CVSS 6.9 EPSS n/a Oct 2, 2026
CVE-2026-64684 MEDIUM

RMCP: Custom HTTP headers leak to cross-origin redirect targets

CVSS 6.8 EPSS 0.50% Sep 16, 2026
CVE-2026-63127 HIGH

RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery

CVSS 8.2 EPSS 0.20% Sep 16, 2026
CVE-2026-63128 HIGH

RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service

CVSS 7.5 EPSS 0.63% Sep 16, 2026
CVE-2026-53937 MEDIUM

MCP Kotlin SDK's unbounded line buffer in StdioServerTransport/StdioClientTransport leads to memory exhaustion (DoS)

CVSS 6.2 EPSS 0.19% Sep 8, 2026
CVE-2026-53965 HIGH

MCP PHP SDK: Unbounded SSE buffer in HttpTransport enables client-side denial of service

CVSS 8.7 EPSS 0.61% Aug 25, 2026
CVE-2026-19753 MEDIUM

Model Context Protocol mcp-rdf-explorer MCP Server server.py explore_url server-side request forgery

CVSS 6.9 EPSS 0.47% Aug 13, 2026
CVE-2026-67432 HIGH

MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport

CVSS 7.5 EPSS 0.78% Jul 29, 2026
CVE-2026-67431 HIGH

MCP Ruby SDK: Ruby SSE Session Poisoning

CVSS 8.3 EPSS 0.48% Jul 29, 2026
CVE-2026-63119 MEDIUM

MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)

CVSS 6.2 EPSS 0.18% Jul 29, 2026
CVE-2026-67430 MEDIUM

MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood

CVSS 5.3 EPSS 0.51% Jul 29, 2026
CVE-2026-63118 MEDIUM

MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection

CVSS 6.9 EPSS 0.26% Jul 29, 2026
CVE-2026-59950 HIGH

MCP Python SDK: WebSocket server transport does not support Host/Origin validation

CVSS 7.6 EPSS 0.23% Jul 15, 2026
CVE-2026-52870 HIGH

MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks

CVSS 7.6 EPSS 0.39% Jul 15, 2026
CVE-2026-52869 HIGH

MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal

CVSS 7.1 EPSS 0.53% Jul 15, 2026
CVE-2026-44428 LOW

MCP Registry: GitHub OIDC tokens replayable across registry deployments due to shared audience

CVSS 2.1 EPSS 0.27% May 14, 2026
Go
CVE-2026-44427 MEDIUM

MCP Registry: Open Redirect

CVSS 5.7 EPSS 0.44% May 14, 2026
Go
CVE-2026-44429 MEDIUM

MCP Registry: Stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl`

CVSS 5.1 EPSS 0.24% May 14, 2026
Go
CVE-2026-44430 MEDIUM

MCP Registry: Unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist

CVSS 6.3 EPSS 0.29% May 14, 2026
Go
CVE-2026-45781 LOW

MCP Registry: OCI ownership validation fails open on upstream rate limits, allowing attacker-controlled package claims

CVSS 3.5 EPSS 0.25% May 14, 2026
Go
CVE-2026-42559 HIGH

RMCP: DNS rebinding vulnerability in rmcp Streamable HTTP server transport

CVSS 8.8 EPSS 0.24% May 14, 2026
crates.ionpm
CVE-2026-35568 HIGH

MCP Java-SDK has a DNS Rebinding Vulnerability

CVSS 7.6 EPSS 0.20% Apr 7, 2026
CVE-2026-34742 HIGH

Model Context Protocol Go SDK: DNS Rebinding Protection Disabled by Default for Servers Running on Localhost

CVSS 7.6 EPSS 0.66% Apr 2, 2026
Go
CVE-2026-34237 MEDIUM

MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)

CVSS 6.1 EPSS 0.31% Mar 31, 2026
CVE-2026-33946 HIGH

MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay

CVSS 8.2 EPSS 0.54% Mar 27, 2026

Showing 1 to 25 CVEs · page 1 (more available)