CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
modelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server.py fetch_url server-side request forgery
RMCP: Custom HTTP headers leak to cross-origin redirect targets
RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery
RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service
MCP Kotlin SDK's unbounded line buffer in StdioServerTransport/StdioClientTransport leads to memory exhaustion (DoS)
MCP PHP SDK: Unbounded SSE buffer in HttpTransport enables client-side denial of service
Model Context Protocol mcp-rdf-explorer MCP Server server.py explore_url server-side request forgery
MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
MCP Ruby SDK: Ruby SSE Session Poisoning
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)
MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood
MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
MCP Python SDK: WebSocket server transport does not support Host/Origin validation
MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
MCP Registry: GitHub OIDC tokens replayable across registry deployments due to shared audience
MCP Registry: Open Redirect
MCP Registry: Stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl`
MCP Registry: Unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist
MCP Registry: OCI ownership validation fails open on upstream rate limits, allowing attacker-controlled package claims
RMCP: DNS rebinding vulnerability in rmcp Streamable HTTP server transport
MCP Java-SDK has a DNS Rebinding Vulnerability
Model Context Protocol Go SDK: DNS Rebinding Protection Disabled by Default for Servers Running on Localhost
MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)
MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay
Showing 1 to 25 CVEs · page 1 (more available)