<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T13:48:15.830353+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-281257</id>
    <title>EUVD-2026-281257</title>
    <updated>2026-10-05T13:48:15.876736+00:00</updated>
    <content>EUVD-2026-281257</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-281257"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35568</id>
    <title>fkie_cve-2026-35568</title>
    <updated>2026-10-05T13:48:15.876772+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to 1.0.0, the java-sdk contains a DNS rebinding vulnerability. This vulnerability allows an attacker to access a locally or network-private java-sdk MCP server via a victims browser that is either local, or network adjacent. This allows an attacker to make any tool call to the server as if they were a locally running MCP connected AI agent. This vulnerability is fixed in 1.0.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-35568"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8jxr-pr72-r468</id>
    <title>GHSA-8jxr-pr72-r468 — Java-SDK has a DNS Rebinding Vulnerability</title>
    <updated>2026-10-05T13:48:15.876805+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: io.modelcontextprotocol.sdk:mcp-core</p>
<p>### Summary</p>
<p>The java-sdk contains a DNS rebinding vulnerability. This vulnerability allows an attacker to access a locally or network-private java-sdk MCP server via a victims browser that is either local, or network adjacent.</p>
<p>This allows an attacker to make any tool call to the server as if they were a locally running MCP connected AI agent.</p>
<p>### Details</p>
<p>Prior to 1.0.0 no Origin header validation was occurring, in violation of the MCP specification. [Base Protocol &gt; Transports: 2.0.1 Security Warning](https://modelcontextprotocol.io/specification/2025-06-18/basic/transports#security-warning):</p>
<p>&gt; 1: Servers MUST validate the Origin header on all incoming connections to prevent DNS rebinding attacks.</p>
<p>When the web server serving HTTP traffic to the MCP server does not perform standard CORS checks, a DNS rebinding attack is possible.</p>
<p>Some default server configurations and frameworks come with embedded `Origin` header validation. MCP servers built using those are not vulnerable to this issue. For example, the following are NOT vulnerable:
- Spring AI</p>
<p>### Impact</p>
<p>Any developer connecting to a malicious website can inadvertently allow an attacker to make tool calls to local or private-network MCP servers.</p>
<p>### Workarounds</p>
<p>Users can mitigate this risk by:
1. Running the MCP server behind a reverse proxy (like Nginx or HAProxy) configured to strictly validate the `Host` and `Origin` headers.
2. Using a framework that inherently enforces strict CORS and Origin validation (such…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8jxr-pr72-r468"/>
  </entry>
</feed>
