Modelcontextprotocol / Registry
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-44428 | MCP Registry: GitHub OIDC tokens replayable across registry deployments due to shared audience | LOW | 2.1 | May 14, 2026 |
| CVE-2026-44427 | MCP Registry: Open Redirect | MEDIUM | 5.7 | May 14, 2026 |
| CVE-2026-44429 | MCP Registry: Stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` | MEDIUM | 5.1 | May 14, 2026 |
| CVE-2026-44430 | MCP Registry: Unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist | MEDIUM | 6.3 | May 14, 2026 |
| CVE-2026-45781 | MCP Registry: OCI ownership validation fails open on upstream rate limits, allowing attacker-controlled package claims | LOW | 3.5 | May 14, 2026 |
Showing 1 to 5 of 5 CVEs