Known Vulnerabilities for Servers by Modelcontextprotocol
Listed below are 10 of the newest known vulnerabilities associated with "Servers" by "Modelcontextprotocol".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-68580 json | FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, s... | Not Provided | 2026-08-02 | 2026-08-05 |
| CVE-2026-67594 json | Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers ... | Not Provided | 2026-07-30 | 2026-07-31 |
| CVE-2026-67531 json | FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute... | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-67432 json | MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transport... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2026-67431 json | MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transport... | Not Provided | 2026-07-29 | 2026-07-30 |
| CVE-2026-67430 json | MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transport... | Not Provided | 2026-07-29 | 2026-07-30 |
| CVE-2026-67353 json | guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Se... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-67339 json | guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL han... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-67332 json | @better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clie... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-66065 json | Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to const... | Not Provided | 2026-08-03 | 2026-08-05 |