CVE-2026-34237 PUBLISHED

MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)

Assigner: GitHub_M
Reserved: 26.03.2026 Published: 31.03.2026 Updated: 31.03.2026

MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to versions 1.0.1 and 1.1.1, there is a hardcoded wildcard CORS vulnerability. This issue has been patched in versions 1.0.1 and 1.1.1.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS Score: 6.1

Product Status

Vendor modelcontextprotocol
Product java-sdk
Versions
  • Version < 1.0.1 is affected
  • Version < 1.1.1 is affected

References

Problem Types

  • CWE-942: Permissive Cross-domain Policy with Untrusted Domains CWE