All 2 CVE vulnerabilities found in java-sdk, with AI-generated Chinese analysis, references, and POCs.
Vendor: modelcontextprotocol
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-35568 | MCP Java-SDK has a DNS Rebinding Vulnerability CWE-346 | 6.3AI | MediumAI | 2026-04-07 |
| CVE-2026-34237 | MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *) CWE-942 | 6.1 | Medium | 2026-03-31 |
All 2 known CVE vulnerabilities affecting java-sdk with full Chinese analysis, references, and POCs where available.