Multiple patched vulnerabilities in n8n and n8n-MCP MCP servers
A cluster of CVEs disclosed in May 2026 affected n8n's MCP OAuth client registration endpoint (unauthenticated memory-exhaustion denial of service) and the n8n-MCP server, which had two server-side request forgery flaws (including IPv6-mapped bypass reaching cloud metadata endpoints and forwarding the n8n API key) and two logging flaws that persisted bearer tokens, API keys and credential-bearing tool arguments in server logs. All issues were fixed in updated releases.
Disclosed 4 May 2026 · Record updated 13 September 2026
Impact
Unauthenticated attackers could render an n8n instance unavailable; attackers supplying n8nApiUrl or x-n8n-url values could force requests to cloud metadata, private networks or localhost with the n8n API key forwarded and responses returned; bearer tokens, per-tenant API keys, OAuth credentials and JSON-RPC payloads could be written to server logs.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42236
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42449
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-41495
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42282
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-44694
