PT-2026-31030 · Unknown · Mcp Java Sdk

Jlleitschuh

·

Published

2026-04-07

·

Updated

2026-04-08

·

CVE-2026-35568

CVSS v4.0

7.6

High

VectorAV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MCP Java SDK versions prior to 1.0.0
Description The MCP Java SDK contains a DNS rebinding vulnerability. This allows an attacker to access a locally or network-private MCP server via a victim's browser. An attacker can then make any tool call to the server as if they were a locally running AI agent. The vulnerability exists because no Origin header validation was occurring, violating the Model Context Protocol (MCP) specification. When the web server serving HTTP traffic to the MCP server does not perform standard CORS checks, a DNS rebinding attack is possible.
Recommendations Update to version 1.0.0 or later. As a workaround, run the MCP server behind a reverse proxy configured to strictly validate the Host and Origin headers. Alternatively, use a framework that inherently enforces strict CORS and Origin validation.

Fix

Origin Validation Error

Weakness Enumeration

Related Identifiers

CVE-2026-35568
GHSA-8JXR-PR72-R468

Affected Products

Mcp Java Sdk