github.com/maximhq/bifrost/transports vulnerabilities
CVEs whose affected-version data names the github.com/maximhq/bifrost/transports package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-90898Critical· 9.8Bifrost registers MCP clients through its management API
Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_conf…
▾ Midnightmaximhq · github.com/maximhq/bifrost/transportsEPSS 0.34%via NVD
CVE-2026-86242High· 8.1Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false)
Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false). T…
▾ Twilightmaximhq · github.com/maximhq/bifrost/transportsEPSS 0.62%via NVD