Vendor
high
advisory
SSRF Vulnerability in Model Context Protocol mcp-rdf-explorer
1 TTP 1 CVEA server-side request forgery (SSRF) vulnerability in the mcp-rdf-explorer MCP server allows remote, unauthenticated attackers to force the server to initiate unauthorized requests.
mcp-rdf-explorer
1t
1c
high
advisory
Session Poisoning Vulnerability in Ruby MCP SDK
1 CVEThe Ruby SDK for the Model Context Protocol (MCP) lacks session ownership validation, allowing attackers to perform unauthorized tool executions within a victim's active session.
Ruby SDK
cve-2026-67431
mcp
session-hijacking
ruby
sse
1c
high
advisory
Java-SDK DNS Rebinding Vulnerability in MCP Server
2 rules 2 TTPsA DNS rebinding vulnerability exists in java-sdk versions prior to 1.0.0, allowing an attacker to access a locally or network-private java-sdk MCP server via a victim's browser, potentially enabling unauthorized tool calls to the server.
Java SDK +1
dns-rebinding
java-sdk
mcp
cve-2026-35568
2r
2t