CVE-2026-34237
Modified
Modified - Updated After Analysis
Hardcoded Wildcard CORS Vulnerability in MCP Java SDK
Publication date: 2026-03-31
Last updated on: 2026-06-09
Assigner: GitHub, Inc.
Description
Description
MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to versions 0.83.0, 1.0.1, and 1.1.1, there is a hardcoded wildcard CORS vulnerability. This issue has been patched in versions 0.83.0, 1.0.1, and 1.1.1.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| lfprojects | mcp_java_sdk | to 1.0.1 (exc) |
| lfprojects | mcp_java_sdk | 1.1.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-942 | The product uses a web-client protection mechanism such as a Content Security Policy (CSP) or cross-domain policy file, but the policy includes untrusted domains with which the web client is allowed to communicate. |