VulnSea

mcp vulnerabilities

CVEs whose affected-version data names the mcp package (pip, rubygems). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

12 CVEsRSS

CVE-2026-94044High· 7.3
2d ago

A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546

A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546. This issue affects the function create_file of the file app/api/mcp/route.ts. Such manipulation of the argument filePath/content lead…

Twilight03-lovepreetSingh · MCPEPSS 0.42%via NVD
CVE-2026-63118Medium
1mo ago

MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection

MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection

Sunlitmcp · mcpEPSS 0.19%via GHSA
CVE-2026-63119Medium· 6.2
1mo ago

MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)

MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)

Sunlitmcp · mcpEPSS 0.13%via GHSA
CVE-2026-67430Medium· 5.3
1mo ago

MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood

MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood

Sunlitmcp · mcpEPSS 0.31%via GHSA
CVE-2026-67432High· 7.5
1mo ago

MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport

MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport

Twilightmcp · mcpEPSS 0.43%via GHSA
CVE-2026-67431High
1mo ago

MCP Ruby SDK: Ruby SSE Session Poisoning

MCP Ruby SDK: Ruby SSE Session Poisoning

Twilightmcp · mcpEPSS 0.29%via GHSA
CVE-2026-52869High· 7.1
2mo ago

MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal

MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal

Twilightmcp · mcpEPSS 0.53%via OSV
CVE-2026-59950High
2mo ago

MCP Python SDK: WebSocket server transport does not support Host/Origin validation

MCP Python SDK: WebSocket server transport does not support Host/Origin validation

Twilightmcp · mcpEPSS 0.23%via OSV
CVE-2026-52870High· 7.6
2mo ago

MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks

MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks

Twilightmcp · mcpEPSS 0.39%via OSV
CVE-2025-66416High
9mo ago

Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default

Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default

Twilightmcp · mcpEPSS 0.51%via OSV
CVE-2025-53365High
1y ago

MCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service

MCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service

Twilightmcp · mcpEPSS 0.37%via OSV
CVE-2025-53366High
1y ago

MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS

MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS

Twilightmcp · mcpEPSS 7.3%via OSV
mcp vulnerabilities (CVEs) · VulnSea