<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:37:57 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-337455</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337455</link>
      <description>EUVD-2026-337455</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337455</guid>
    </item>
    <item>
      <title>fkie_cve-2026-25536</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25536</link>
      <description>&lt;p&gt;MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reused across multiple client connections, most commonly in stateless StreamableHTTPServerTransport deployments. This issue has been patched in version 1.26.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reused across multiple client connections, most commonly in stateless StreamableHTTPServerTransport deployments. This issue has been patched in version 1.26.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-25536</guid>
    </item>
    <item>
      <title>GHSA-345p-7cg4-v4c7 — @modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-345p-7cg4-v4c7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @modelcontextprotocol/sdk&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Cross-client data leak via two distinct issues: (1) reusing a single `StreamableHTTPServerTransport` across multiple client requests, and (2) reusing a single `McpServer`/`Server` instance across multiple transports. Both are most common in stateless deployments.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This advisory covers two related but distinct vulnerabilities. A deployment may be affected by one or both.&lt;/p&gt;
&lt;p&gt;#### Issue 1: Transport re-use&lt;/p&gt;
&lt;p&gt;**What happens:** When a single `StreamableHTTPServerTransport` instance handles multiple client requests, JSON-RPC message ID collisions cause responses to be routed to the wrong client&amp;#39;s HTTP connection. The transport maintains an internal `requestId → stream` mapping, and since MCP client SDKs generate message IDs using an incrementing counter starting at 0, two clients produce identical IDs. The second client&amp;#39;s request overwrites the first client&amp;#39;s mapping entry, routing the response to the wrong HTTP stream.&lt;/p&gt;
&lt;p&gt;**What is affected:** All request types — `tools/call`, `resources/read`, `prompts/get`, etc. No server-initiated features are required to trigger this.&lt;/p&gt;
&lt;p&gt;**Conditions:**
- A single `StreamableHTTPServerTransport` instance is reused across multiple client requests (most common in stateless mode without `sessionIdGenerator`)
- Two or more clients send requests concurrently
- Clients generate overlapping JSON-RPC message IDs (the SDK&amp;#39;s default client uses an incrementing counter starting at 0)&lt;/p&gt;
&lt;p&gt;#### Issue 2: Server/Protocol re-use&lt;/p&gt;
&lt;p&gt;**What happen…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @modelcontextprotocol/sdk&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Cross-client data leak via two distinct issues: (1) reusing a single `StreamableHTTPServerTransport` across multiple client requests, and (2) reusing a single `McpServer`/`Server` instance across multiple transports. Both are most common in stateless deployments.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This advisory covers two related but distinct vulnerabilities. A deployment may be affected by one or both.&lt;/p&gt;
&lt;p&gt;#### Issue 1: Transport re-use&lt;/p&gt;
&lt;p&gt;**What happens:** When a single `StreamableHTTPServerTransport` instance handles multiple client requests, JSON-RPC message ID collisions cause responses to be routed to the wrong client&amp;#39;s HTTP connection. The transport maintains an internal `requestId → stream` mapping, and since MCP client SDKs generate message IDs using an incrementing counter starting at 0, two clients produce identical IDs. The second client&amp;#39;s request overwrites the first client&amp;#39;s mapping entry, routing the response to the wrong HTTP stream.&lt;/p&gt;
&lt;p&gt;**What is affected:** All request types — `tools/call`, `resources/read`, `prompts/get`, etc. No server-initiated features are required to trigger this.&lt;/p&gt;
&lt;p&gt;**Conditions:**
- A single `StreamableHTTPServerTransport` instance is reused across multiple client requests (most common in stateless mode without `sessionIdGenerator`)
- Two or more clients send requests concurrently
- Clients generate overlapping JSON-RPC message IDs (the SDK&amp;#39;s default client uses an incrementing counter starting at 0)&lt;/p&gt;
&lt;p&gt;#### Issue 2: Server/Protocol re-use&lt;/p&gt;
&lt;p&gt;**What happen…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-345p-7cg4-v4c7</guid>
    </item>
    <item>
      <title>RHSA-2026:3960 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Container Release Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:3960</link>
      <description>&lt;p&gt;python-protobuf: Unbounded recursion in Python Protobuf lodash: prototype pollution in _.unset and _.omit functions aiohttp: AIOHTTP HTTP Request/Response Smuggling react-router: @remix-run/router: React Router XSS Vulnerability jsonpath: jsonpath: Prototype Pollution vulnerability in the value function golang: net/url: Memory exhaustion in query parameter parsing in net/url urllib3: urllib3 Streaming API improperly handles highly compressed data aiohttp: AIOHTTP&amp;#39;s HTTP Parser auto_decompress feature is vulnerable to zip bomb Django: Django: SQL Injection via RasterField band index parameter Django: Django: SQL Injection via crafted column aliases Django: Django: SQL injection via crafted column aliases in QuerySet.order_by() urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) react-router: @remix-run/react: React Router SSR XSS in ScrollRestoration @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking python-multipart: Python-Multipart: Arbitrary file write via path traversal vulnerability @modelcontextprotocol/sdk: @modelcontextprotocol/sdk cross-client data leak&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python-protobuf: Unbounded recursion in Python Protobuf lodash: prototype pollution in _.unset and _.omit functions aiohttp: AIOHTTP HTTP Request/Response Smuggling react-router: @remix-run/router: React Router XSS Vulnerability jsonpath: jsonpath: Prototype Pollution vulnerability in the value function golang: net/url: Memory exhaustion in query parameter parsing in net/url urllib3: urllib3 Streaming API improperly handles highly compressed data aiohttp: AIOHTTP&amp;#39;s HTTP Parser auto_decompress feature is vulnerable to zip bomb Django: Django: SQL Injection via RasterField band index parameter Django: Django: SQL Injection via crafted column aliases Django: Django: SQL injection via crafted column aliases in QuerySet.order_by() urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) react-router: @remix-run/react: React Router SSR XSS in ScrollRestoration @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking python-multipart: Python-Multipart: Arbitrary file write via path traversal vulnerability @modelcontextprotocol/sdk: @modelcontextprotocol/sdk cross-client data leak&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:3960</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0574 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0574</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um einen Denial of Service Angriff durchzuführen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um einen Denial of Service Angriff durchzuführen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0574</guid>
    </item>
  </channel>
</rss>
