MCP Registry是Model Context Protocol开源的一个MCP服务器应用商店。 MCP Registry 1.7.9之前版本存在安全漏洞,该漏洞源于OCI所有权验证在HTTP 429时跳过标签匹配检查,可能导致命名空间绑定到未控制的镜像。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| modelcontextprotocol | registry | < 1.7.9 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| modelcontextprotocol | registry | < 1.7.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42559 | 8.8 HIGH | RMCP: DNS rebinding vulnerability in rmcp Streamable HTTP server transport |
| CVE-2026-44429 | MCP Registry: Stored XSS in catalogue UI via attribute-quote breakout in publisher-control | |
| CVE-2026-44430 | MCP Registry: Unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site- | |
| CVE-2026-44427 | MCP Registry: Open Redirect | |
| CVE-2026-44428 | MCP Registry: GitHub OIDC tokens replayable across registry deployments due to shared audi |
No comments yet