<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 16:59:58 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-326253</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-326253</link>
      <description>EUVD-2026-326253</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-326253</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34237</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34237</link>
      <description>&lt;p&gt;MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to versions 0.83.0, 1.0.1, and 1.1.1, there is a hardcoded wildcard CORS vulnerability. This issue has been patched in versions 0.83.0, 1.0.1, and 1.1.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to versions 0.83.0, 1.0.1, and 1.1.1, there is a hardcoded wildcard CORS vulnerability. This issue has been patched in versions 0.83.0, 1.0.1, and 1.1.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34237</guid>
    </item>
    <item>
      <title>GHSA-hv2w-8mjj-jw22 — MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hv2w-8mjj-jw22</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.modelcontextprotocol.sdk:mcp-core&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;**Hardcoded Wildcard CORS (Access-Control-Allow-Origin: * )**&lt;/p&gt;
&lt;p&gt;- https://github.com/modelcontextprotocol/java-sdk/blob/main/mcp-core/src/main/java/io/modelcontextprotocol/server/transport/HttpServletSseServerTransportProvider.java#L289
- https://github.com/modelcontextprotocol/java-sdk/blob/main/mcp-core/src/main/java/io/modelcontextprotocol/server/transport/HttpServletStreamableServerTransportProvider.java#L525&lt;/p&gt;
&lt;p&gt;### Attack Scenario
An attacker-controlled web page instructs the victim&amp;#39;s browser to open GET https://internal-mcp-server/sse. Because Access-Control-Allow-Origin: * allows cross-origin SSE reads, the attacker&amp;#39;s page receives the endpoint event — which contains the session ID. The attacker can then POST to that endpoint from their page using the victim&amp;#39;s browser as a relay.&lt;/p&gt;
&lt;p&gt;### Comparison with python-sdk
No Access-Control-Allow-Origin header is emitted by either Python transport. The browser&amp;#39;s default same-origin policy remains in full effect.
https://github.com/modelcontextprotocol/python-sdk/blob/main/src/mcp/server/sse.py
https://github.com/modelcontextprotocol/python-sdk/blob/main/src/mcp/server/streamable_http.py&lt;/p&gt;
&lt;p&gt;### Recommendation
In the SDK, the transport layer should not own CORS policy. Server implementors who need cross-origin access can add a CORS filter at the servlet filter or Spring Security layer.&lt;/p&gt;
&lt;p&gt;### Reference&lt;/p&gt;
&lt;p&gt;- https://cheatsheetseries.owasp.org/cheatsheets/HTTP_Headers_Cheat_Sheet.html#access-control-allow-origin&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.modelcontextprotocol.sdk:mcp-core&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;**Hardcoded Wildcard CORS (Access-Control-Allow-Origin: * )**&lt;/p&gt;
&lt;p&gt;- https://github.com/modelcontextprotocol/java-sdk/blob/main/mcp-core/src/main/java/io/modelcontextprotocol/server/transport/HttpServletSseServerTransportProvider.java#L289
- https://github.com/modelcontextprotocol/java-sdk/blob/main/mcp-core/src/main/java/io/modelcontextprotocol/server/transport/HttpServletStreamableServerTransportProvider.java#L525&lt;/p&gt;
&lt;p&gt;### Attack Scenario
An attacker-controlled web page instructs the victim&amp;#39;s browser to open GET https://internal-mcp-server/sse. Because Access-Control-Allow-Origin: * allows cross-origin SSE reads, the attacker&amp;#39;s page receives the endpoint event — which contains the session ID. The attacker can then POST to that endpoint from their page using the victim&amp;#39;s browser as a relay.&lt;/p&gt;
&lt;p&gt;### Comparison with python-sdk
No Access-Control-Allow-Origin header is emitted by either Python transport. The browser&amp;#39;s default same-origin policy remains in full effect.
https://github.com/modelcontextprotocol/python-sdk/blob/main/src/mcp/server/sse.py
https://github.com/modelcontextprotocol/python-sdk/blob/main/src/mcp/server/streamable_http.py&lt;/p&gt;
&lt;p&gt;### Recommendation
In the SDK, the transport layer should not own CORS policy. Server implementors who need cross-origin access can add a CORS filter at the servlet filter or Spring Security layer.&lt;/p&gt;
&lt;p&gt;### Reference&lt;/p&gt;
&lt;p&gt;- https://cheatsheetseries.owasp.org/cheatsheets/HTTP_Headers_Cheat_Sheet.html#access-control-allow-origin&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hv2w-8mjj-jw22</guid>
    </item>
  </channel>
</rss>
