Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 27+

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Examples: RCE · SSRF · GHSA · log4j
Filter
Clear filters
High
MCP Ruby SDK Transport Layer DoS Fix: Max Request Size Limits
github.com · 2026-07-30
modelcontextprotocol/ruby-sdk
Read more
High
CVE-2024-67432: Uncontrolled Memory Allocation DoS in MCP Ruby SDK with PoC
CVE-2024-67432 · github.com · 2026-07-30
modelcontextprotocol/ruby-sdk
Read more
High
Ruby MCP SDK SSE Session Hijacking Vulnerability (CVE-2026-67431) Analysis
CVE-2026-67431 · github.com · 2026-07-30
Ruby MCP SDK <= 0.22.0
Read more
Medium
StreamableHTTPTransport Session Exhaustion DoS Vulnerability and Fix Analysis
github.com · 2026-07-30
modelcontextprotocol/ruby-sdk (default configuration without session timeout)
Read more
Medium
MCP::Server Stdio Unbounded Line Buffer DoS (CVE-less)
github.com · 2026-07-30
modelcontextprotocol/ruby-sdk <= 0.22.0
Read more
High
MCP Ruby StdioTransport DoS Vulnerability: Unbounded stdin Read Causes OOM
github.com · 2026-07-30
modelcontextprotocol/ruby-sdk
Read more
High
MCP StreamableHTTPTransport DNS Rebinding Vulnerability and Fix
github.com · 2026-07-30
ModelContextProtocol Ruby SDK <= latest
Read more
Medium
CVE-2026-6318: DNS Rebinding Vulnerability in mcp gem with POC
CVE-2026-6318 · github.com · 2026-07-30
mcp gem <= 0.22.0
Read more
Unknown
Fix: Apply TransportSecuritySettings to WebSocket Server Transport
github.com · 2026-07-16
modelcontextprotocol/python-sdk v1.x
Read more
High
MCP WebSocket Server Missing Host/Origin Validation Vulnerability (CVE-2026-59950)
CVE-2026-59950 · github.com · 2026-07-16
modelcontextprotocol/python-sdk < 1.28.1
Read more
High
MCP WebSocket Server Request Header Validation Fix
github.com · 2026-07-16
modelcontextprotocol/python-sdk v1.x
Read more
High
FastAPI Experimental Task Feature Unauthorized Access/Bypass (CVE-2024-52870)
CVE-2024-52870 · github.com · 2026-07-16
modelcontextprotocol/python-sdk >= 1.23.0 · modelcontextprotocol/python-sdk <= 1.27.1
Read more
Premium intel
High
MCP Server Auth Session Hijacking Fix: Bearer/SSE Validation
github.com · 2026-07-16
modelcontextprotocol/python-sdk v1.x
Read more
Premium intel
Unknown
MCP Server Auth: Fix Access Token Missing 'sub' and 'claims' Fields
github.com · 2026-07-16
modelcontextprotocol/python-sdk
Read more
Critical
GitLab gitlab-shell RCE Vulnerability CVE-2024-39934 Analysis and Fix
CVE-2024-39934 · github.com · 2026-04-03
GitLab 16.0.0 to 16.7.0 · GitLab 15.0.0 to 15.11.0 …
Read more
High
MCP Go SDK Default DNS Rebinding Protection Disabled on Localhost
github.com · 2026-04-03
Model Context Protocol Go SDK < 1.4.0
Read more
High
fio: Fix for DNS rebinding attack on localhost server
github.com · 2026-04-03
fio (all versions prior to the fix in PR #760 / #7150)
Read more
High
Puppet Forge Fixes Arbitrary Code Execution in puppet-lint
github.com · 2026-04-03
puppet-lint < 2.5.3
Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.