<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 03:27:25 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-281257</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-281257</link>
      <description>EUVD-2026-281257</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-281257</guid>
    </item>
    <item>
      <title>fkie_cve-2026-35568</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35568</link>
      <description>&lt;p&gt;MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to 1.0.0, the java-sdk contains a DNS rebinding vulnerability. This vulnerability allows an attacker to access a locally or network-private java-sdk MCP server via a victims browser that is either local, or network adjacent. This allows an attacker to make any tool call to the server as if they were a locally running MCP connected AI agent. This vulnerability is fixed in 1.0.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to 1.0.0, the java-sdk contains a DNS rebinding vulnerability. This vulnerability allows an attacker to access a locally or network-private java-sdk MCP server via a victims browser that is either local, or network adjacent. This allows an attacker to make any tool call to the server as if they were a locally running MCP connected AI agent. This vulnerability is fixed in 1.0.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-35568</guid>
    </item>
    <item>
      <title>GHSA-8jxr-pr72-r468 — Java-SDK has a DNS Rebinding Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8jxr-pr72-r468</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.modelcontextprotocol.sdk:mcp-core&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The java-sdk contains a DNS rebinding vulnerability. This vulnerability allows an attacker to access a locally or network-private java-sdk MCP server via a victims browser that is either local, or network adjacent.&lt;/p&gt;
&lt;p&gt;This allows an attacker to make any tool call to the server as if they were a locally running MCP connected AI agent.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Prior to 1.0.0 no Origin header validation was occurring, in violation of the MCP specification. [Base Protocol &amp;gt; Transports: 2.0.1 Security Warning](https://modelcontextprotocol.io/specification/2025-06-18/basic/transports#security-warning):&lt;/p&gt;
&lt;p&gt;&amp;gt; 1: Servers MUST validate the Origin header on all incoming connections to prevent DNS rebinding attacks.&lt;/p&gt;
&lt;p&gt;When the web server serving HTTP traffic to the MCP server does not perform standard CORS checks, a DNS rebinding attack is possible.&lt;/p&gt;
&lt;p&gt;Some default server configurations and frameworks come with embedded `Origin` header validation. MCP servers built using those are not vulnerable to this issue. For example, the following are NOT vulnerable:
- Spring AI&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Any developer connecting to a malicious website can inadvertently allow an attacker to make tool calls to local or private-network MCP servers.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Users can mitigate this risk by:
1. Running the MCP server behind a reverse proxy (like Nginx or HAProxy) configured to strictly validate the `Host` and `Origin` headers.
2. Using a framework that inherently enforces strict CORS and Origin validation (such…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.modelcontextprotocol.sdk:mcp-core&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The java-sdk contains a DNS rebinding vulnerability. This vulnerability allows an attacker to access a locally or network-private java-sdk MCP server via a victims browser that is either local, or network adjacent.&lt;/p&gt;
&lt;p&gt;This allows an attacker to make any tool call to the server as if they were a locally running MCP connected AI agent.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Prior to 1.0.0 no Origin header validation was occurring, in violation of the MCP specification. [Base Protocol &amp;gt; Transports: 2.0.1 Security Warning](https://modelcontextprotocol.io/specification/2025-06-18/basic/transports#security-warning):&lt;/p&gt;
&lt;p&gt;&amp;gt; 1: Servers MUST validate the Origin header on all incoming connections to prevent DNS rebinding attacks.&lt;/p&gt;
&lt;p&gt;When the web server serving HTTP traffic to the MCP server does not perform standard CORS checks, a DNS rebinding attack is possible.&lt;/p&gt;
&lt;p&gt;Some default server configurations and frameworks come with embedded `Origin` header validation. MCP servers built using those are not vulnerable to this issue. For example, the following are NOT vulnerable:
- Spring AI&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Any developer connecting to a malicious website can inadvertently allow an attacker to make tool calls to local or private-network MCP servers.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Users can mitigate this risk by:
1. Running the MCP server behind a reverse proxy (like Nginx or HAProxy) configured to strictly validate the `Host` and `Origin` headers.
2. Using a framework that inherently enforces strict CORS and Origin validation (such…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8jxr-pr72-r468</guid>
    </item>
  </channel>
</rss>
