VulnSea

CWE-350

CVEs classified under CWE-350, newest first.

10 CVEsRSS

CVE-2026-61568Critical· 9.6
6d ago

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route bro…

Midnightzereight · @zereight/mcp-gitlabEPSS 0.32%via NVD
CVE-2026-53708Medium· 6.6PoC
1w ago

ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs

ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs. Prior to 1.0.3, the /admin/gateways/test call site in mcpgateway/admin.py calls valid…

TwilightIBM · mcp-context-forgeEPSS 0.28%via NVD
CVE-2026-57123Critical· 9.8
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_server bind to 0.0.0.0 and create /sse and /messages/ routes without invoking the available SecurityConfig authenticati…

MidnightMervinPraison · praisonaiagentsEPSS 0.47%via NVD
CVE-2026-55526High· 8.5
3w ago

praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)

praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)

Twilightpraisonaiagents · praisonaiagentsEPSS 0.21%via OSV
CVE-2026-75514Medium· 5.9
1mo ago

BunkerWeb is an open-source, next-generation Web Application Firewall

BunkerWeb is an open-source, next-generation Web Application Firewall. Prior to 1.6.13, the blacklist, greylist, and antibot modules in src/common/core/blacklist/blacklist.lua, src/common/core/greylist/greylist.lua, and src/common/core/a…

SunlitEPSS 0.46%via NVD
CVE-2026-63118Medium
1mo ago

MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection

MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection

Sunlitmcp · mcpEPSS 0.19%via GHSA
CVE-2026-55391High· 7.5
1mo ago

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.24%via OSV
CVE-2026-46611Medium· 5.3
3mo ago

Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack

Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack

Sunlitglances · glancesEPSS 0.17%via GHSA
GHSA-x227-pf99-vffgCritical· 9.8
3mo ago

PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in

PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in

Midnightpraisonaiagents · praisonaiagentsvia GHSA
CVE-2026-24281High· 7.4
6mo ago

Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certifica…

Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certifica…

Twilightapache · zookeeperEPSS 0.63%via NVD
CWE-350 vulnerabilities (CVEs) · VulnSea