Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Origin-validation flaws in official MCP Java and Go SDKs allow cross-site access

Two vulnerabilities disclosed in the official Model Context Protocol SDKs: the Java SDK shipped a hardcoded wildcard CORS policy (CVE-2026-34237) and the Go SDK did not enable DNS rebinding protection by default for HTTP-based servers (CVE-2026-34742), letting a malicious website reach an unauthenticated local MCP server and invoke its tools or resources. Both issues were patched in updated SDK releases.

Disclosed 31 March 2026 · Record updated 13 September 2026

Impact

A malicious website could bypass same-origin restrictions to send requests to a local, unauthenticated MCP server and invoke tools or access resources on behalf of the user.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-34237
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-34742