CVE Feed

    Dashboard / CVE / CVE-2026-35568

    CVE-2026-35568

    MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to 1.0.0, the java-sdk contains a DNS rebinding vulnerability. This vulnerability allows an attacker to access a locally or network-private java-sdk MCP server via a victims browser that is either local, or network adjacent. This allows an attacker to make any tool call to the server as if they were a locally running MCP connected AI agent. This vulnerability is fixed in 1.0.0.

    Published:Apr 7, 2026
    Last Modified:Apr 15, 2026
    EPS:Apr 7, 2026
    EPSS Score:0.00017
    CVSS Score:5.7

    Affected Products

    Vendor
    Lfprojects
    Product
    Mcp Java Sdk
    Vendor
    Modelcontextprotocol
    Product
    Java-sdk

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High