Known Vulnerabilities for Transport-http by Wso2
Listed below are 1 of the newest known vulnerabilities associated with "Transport-http" by "Wso2".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-61427 json | PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key option def... | Not Provided | 2026-07-15 | 2026-07-16 |
| CVE-2026-59725 json | Socket.IO enables bidirectional and low-latency communication for every platform. From 4.1.0 before 6.6.7, Engine.IO protocol... | Not Provided | 2026-07-08 | 2026-07-08 |
| CVE-2026-55605 json | DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.8.0, the self-hosted H... | Not Provided | 2026-07-09 | 2026-07-10 |
| CVE-2026-54309 json | n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run in HTTP transpor... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-50287 json | AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a Strea... | Not Provided | 2026-06-12 | 2026-06-15 |
| CVE-2026-49949 json | CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercept sen... | Not Provided | 2026-06-11 | 2026-07-14 |
| CVE-2026-49357 json | Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly operat... | Not Provided | 2026-06-19 | 2026-06-22 |
| CVE-2026-48743 json | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and ... | Not Provided | 2026-06-26 | 2026-06-29 |
| CVE-2026-48480 json | The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.22.FInal, the codec-ohttp impleme... | Not Provided | 2026-06-04 | 2026-06-04 |
| CVE-2026-47323 json | Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStrategy ... | Not Provided | 2026-05-19 | 2026-07-15 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wso2 | Transport-http | 6.3.8 | |||
| Application | Wso2 | Transport-http | 6.3.7 | |||
| Application | Wso2 | Transport-http | 6.3.6 | |||
| Application | Wso2 | Transport-http | 6.3.5 | |||
| Application | Wso2 | Transport-http | 6.3.4 | |||
| Application | Wso2 | Transport-http | 6.3.3 | |||
| Application | Wso2 | Transport-http | 6.3.2 | |||
| Application | Wso2 | Transport-http | 6.3.1 | |||
| Application | Wso2 | Transport-http | 6.3.0 | |||
| Application | Wso2 | Transport-http | 6.2.9 | |||
| Application | Wso2 | Transport-http | 6.2.8 | |||
| Application | Wso2 | Transport-http | 6.2.7 | |||
| Application | Wso2 | Transport-http | 6.2.6 | |||
| Application | Wso2 | Transport-http | 6.2.5 | |||
| Application | Wso2 | Transport-http | 6.2.4 | |||
| Application | Wso2 | Transport-http | 6.2.34 | |||
| Application | Wso2 | Transport-http | 6.2.33 | |||
| Application | Wso2 | Transport-http | 6.2.32 | |||
| Application | Wso2 | Transport-http | 6.2.31 | |||
| Application | Wso2 | Transport-http | 6.2.30 |