<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T20:38:19.070106+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337455</id>
    <title>EUVD-2026-337455</title>
    <updated>2026-10-03T20:38:19.079508+00:00</updated>
    <content>EUVD-2026-337455</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337455"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25536</id>
    <title>fkie_cve-2026-25536</title>
    <updated>2026-10-03T20:38:19.079548+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reused across multiple client connections, most commonly in stateless StreamableHTTPServerTransport deployments. This issue has been patched in version 1.26.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-25536"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-345p-7cg4-v4c7</id>
    <title>GHSA-345p-7cg4-v4c7 — @modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse</title>
    <updated>2026-10-03T20:38:19.079583+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @modelcontextprotocol/sdk</p>
<p>### Summary</p>
<p>Cross-client data leak via two distinct issues: (1) reusing a single `StreamableHTTPServerTransport` across multiple client requests, and (2) reusing a single `McpServer`/`Server` instance across multiple transports. Both are most common in stateless deployments.</p>
<p>### Impact</p>
<p>This advisory covers two related but distinct vulnerabilities. A deployment may be affected by one or both.</p>
<p>#### Issue 1: Transport re-use</p>
<p>**What happens:** When a single `StreamableHTTPServerTransport` instance handles multiple client requests, JSON-RPC message ID collisions cause responses to be routed to the wrong client's HTTP connection. The transport maintains an internal `requestId → stream` mapping, and since MCP client SDKs generate message IDs using an incrementing counter starting at 0, two clients produce identical IDs. The second client's request overwrites the first client's mapping entry, routing the response to the wrong HTTP stream.</p>
<p>**What is affected:** All request types — `tools/call`, `resources/read`, `prompts/get`, etc. No server-initiated features are required to trigger this.</p>
<p>**Conditions:**
- A single `StreamableHTTPServerTransport` instance is reused across multiple client requests (most common in stateless mode without `sessionIdGenerator`)
- Two or more clients send requests concurrently
- Clients generate overlapping JSON-RPC message IDs (the SDK's default client uses an incrementing counter starting at 0)</p>
<p>#### Issue 2: Server/Protocol re-use</p>
<p>**What happen…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-345p-7cg4-v4c7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:3960</id>
    <title>RHSA-2026:3960 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Container Release Update</title>
    <updated>2026-10-03T20:38:19.079658+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python-protobuf: Unbounded recursion in Python Protobuf lodash: prototype pollution in _.unset and _.omit functions aiohttp: AIOHTTP HTTP Request/Response Smuggling react-router: @remix-run/router: React Router XSS Vulnerability jsonpath: jsonpath: Prototype Pollution vulnerability in the value function golang: net/url: Memory exhaustion in query parameter parsing in net/url urllib3: urllib3 Streaming API improperly handles highly compressed data aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb Django: Django: SQL Injection via RasterField band index parameter Django: Django: SQL Injection via crafted column aliases Django: Django: SQL injection via crafted column aliases in QuerySet.order_by() urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) react-router: @remix-run/react: React Router SSR XSS in ScrollRestoration @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking python-multipart: Python-Multipart: Arbitrary file write via path traversal vulnerability @modelcontextprotocol/sdk: @modelcontextprotocol/sdk cross-client data leak</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:3960"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0574</id>
    <title>WID-SEC-W-2026-0574 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
    <updated>2026-10-03T20:38:19.079698+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um einen Denial of Service Angriff durchzuführen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, und um einen Cross-Site Scripting Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0574"/>
  </entry>
</feed>
