<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:46:57 +0000</lastBuildDate>
    <item>
      <title>CLEANSTART-2026-BU71031 — Security fix for CVE-2026-34742 applied in: gptscript 0.9.8-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bu71031</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: gptscript&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the gptscript package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: gptscript&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the gptscript package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bu71031</guid>
    </item>
    <item>
      <title>EUVD-2026-337308</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337308</link>
      <description>EUVD-2026-337308</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337308</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34742</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34742</link>
      <description>&lt;p&gt;The Go MCP SDK used Go&amp;#39;s standard encoding/json. Prior to version 1.4.0, the Model Context Protocol (MCP) Go SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on localhost without authentication with StreamableHTTPHandler or SSEHandler, a malicious website could exploit DNS rebinding to bypass same-origin policy restrictions and send requests to the local MCP server. This could allow an attacker to invoke tools or access resources exposed by the MCP server on behalf of the user in those limited circumstances. This issue has been patched in version 1.4.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Go MCP SDK used Go&amp;#39;s standard encoding/json. Prior to version 1.4.0, the Model Context Protocol (MCP) Go SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on localhost without authentication with StreamableHTTPHandler or SSEHandler, a malicious website could exploit DNS rebinding to bypass same-origin policy restrictions and send requests to the local MCP server. This could allow an attacker to invoke tools or access resources exposed by the MCP server on behalf of the user in those limited circumstances. This issue has been patched in version 1.4.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34742</guid>
    </item>
    <item>
      <title>GHSA-xw59-hvm2-8pj6 — DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xw59-hvm2-8pj6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/modelcontextprotocol/go-sdk&lt;/p&gt;
&lt;p&gt;The Model Context Protocol (MCP) Go SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on localhost without authentication with `StreamableHTTPHandler` or `SSEHandler`, a malicious website could exploit DNS rebinding to bypass same-origin policy restrictions and send requests to the local MCP server. This could allow an attacker to invoke tools or access resources exposed by the MCP server on behalf of the user in those limited circumstances.&lt;/p&gt;
&lt;p&gt;Note that running HTTP-based MCP servers locally without authentication is not recommended per MCP security best practices. This issue does not affect servers using stdio transport.&lt;/p&gt;
&lt;p&gt;Servers created via `StreamableHTTPHandler` or `SSEHandler` now have this protection enabled by default when binding to `localhost`. Users are advised to update to version `1.4.0` to receive this automatic protection.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/modelcontextprotocol/go-sdk&lt;/p&gt;
&lt;p&gt;The Model Context Protocol (MCP) Go SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on localhost without authentication with `StreamableHTTPHandler` or `SSEHandler`, a malicious website could exploit DNS rebinding to bypass same-origin policy restrictions and send requests to the local MCP server. This could allow an attacker to invoke tools or access resources exposed by the MCP server on behalf of the user in those limited circumstances.&lt;/p&gt;
&lt;p&gt;Note that running HTTP-based MCP servers locally without authentication is not recommended per MCP security best practices. This issue does not affect servers using stdio transport.&lt;/p&gt;
&lt;p&gt;Servers created via `StreamableHTTPHandler` or `SSEHandler` now have this protection enabled by default when binding to `localhost`. Users are advised to update to version `1.4.0` to receive this automatic protection.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xw59-hvm2-8pj6</guid>
    </item>
    <item>
      <title>RHSA-2026:21772 — Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.28.0 Release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:21772</link>
      <description>&lt;p&gt;bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression undici: undici: Denial of Service via crafted WebSocket frame with large length org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requests undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter markdown-it: markdown-it: Denial of Service via Regular Expression Denial of Service in linkify function bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions svgo: SVGO: Denial of Service via XML entity expansion express-rate-limit: express-rate-limit: Denial of Service for IPv4 clients due to incorrect IPv6 subnet masking tar: tar: File overwrite via drive-relative symlink traversal flatted: flatted: Unbounded recursion DoS in parse() revive phase crypto/x509: crypto/tls: golang: Go: Denial of Service vulnera…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression undici: undici: Denial of Service via crafted WebSocket frame with large length org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requests undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter markdown-it: markdown-it: Denial of Service via Regular Expression Denial of Service in linkify function bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions svgo: SVGO: Denial of Service via XML entity expansion express-rate-limit: express-rate-limit: Denial of Service for IPv4 clients due to incorrect IPv6 subnet masking tar: tar: File overwrite via drive-relative symlink traversal flatted: flatted: Unbounded recursion DoS in parse() revive phase crypto/x509: crypto/tls: golang: Go: Denial of Service vulnera…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:21772</guid>
    </item>
  </channel>
</rss>
