dynoxide-rs
A DynamoDB emulator in Rust, backed by SQLite. Starts in milliseconds as a single static binary, and is verified against real AWS by a public conformance suite. Runs as an HTTP server, an MCP server for coding agents, an embeddable library, or in the browser via WebAssembly.
Activity
- Latest release
- 5h ago
- Total releases
- 21
- Cadence
- ~6 days
- Last 12 months
- 21
Reach
- Downloads
- 735
- Stars
- 88
Details
- License
- MIT OR Apache-2.0
- First release
- Feb 14, 2026
| Version | Released | |
|---|---|---|
2.0.0
major
|
2.0.0
major
Dependencies (47)
+ 39 more
Changelog
Compare changes
|
|
1.1.0
minor
|
1.1.0
minor
Dependencies (46)
+ 38 more
Changelog
Compare changes
|
|
1.0.0
major
|
1.0.0
major
Dependencies (46)
+ 38 more
Changelog
Compare changes
|
|
0.13.0
minor
|
0.13.0
minor
Dependencies (45)
+ 37 more
Changelog
Compare changes
|
|
0.12.0
minor
|
0.12.0
minor
Dependencies (45)
+ 37 more
Changelog
Compare changes
|
|
0.11.4
patch
|
0.11.4
patch
Dependencies (45)
+ 37 more
Changelog
Compare changes
|
|
0.11.3
patch
|
0.11.3
patch
Dependencies (45)
+ 37 more
Changelog
Compare changes
|
|
0.11.2
patch
|
0.11.2
patch
Dependencies (44)
+ 36 more
Changelog
Compare changes
|
|
0.11.1
patch
|
0.11.1
patch
Dependencies (44)
+ 36 more
Changelog
Compare changes
|
|
0.11.0
minor
|
0.11.0
minor
Dependencies (44)
+ 36 more
Changelog
Compare changes
|
|
0.10.0
minor
|
0.10.0
minor
Dependencies (44)
+ 36 more
Changelog
Compare changes
|
|
0.9.13
patch
|
0.9.13
patch
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
0.9.12
patch
1 CVE
CVE-2026-42559
GHSA-fvh2-gm75-j4j7
GHSA-89vp-x53w-74fx
RUSTSEC-2026-0140
RUSTSEC-2026-0189
May 18, 2026
dynoxide: DNS rebinding and cross-origin CSRF via MCP HTTP transport
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summarydynoxide's MCP HTTP transport was vulnerable to DNS rebinding via its transitive ImpactIf a user is running Reachable tools include reads ( Any data in tables that the local dynoxide instance has access to can be read, modified, or destroyed. Patchesdynoxide 0.9.13 closes both the named CVE and a related cross-origin CSRF gap:
Native MCP clients that don't send an Origin header (Claude Code, Cursor, the dynoxide CLI) are unaffected by the Origin check and continue to work. Workarounds
Resources
CreditsVulnerability identified via GitHub Dependabot alert on the transitive rmcp dependency. Fixed in
0.9.13
References Updated Jun 29, 2026 · Source: OSV.dev |
0.9.12
patch
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
0.9.11
patch
1 CVE
CVE-2026-42559
GHSA-fvh2-gm75-j4j7
GHSA-89vp-x53w-74fx
RUSTSEC-2026-0140
RUSTSEC-2026-0189
May 18, 2026
dynoxide: DNS rebinding and cross-origin CSRF via MCP HTTP transport
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summarydynoxide's MCP HTTP transport was vulnerable to DNS rebinding via its transitive ImpactIf a user is running Reachable tools include reads ( Any data in tables that the local dynoxide instance has access to can be read, modified, or destroyed. Patchesdynoxide 0.9.13 closes both the named CVE and a related cross-origin CSRF gap:
Native MCP clients that don't send an Origin header (Claude Code, Cursor, the dynoxide CLI) are unaffected by the Origin check and continue to work. Workarounds
Resources
CreditsVulnerability identified via GitHub Dependabot alert on the transitive rmcp dependency. Fixed in
0.9.13
References Updated Jun 29, 2026 · Source: OSV.dev |
0.9.11
patch
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
0.9.10
patch
1 CVE
CVE-2026-42559
GHSA-fvh2-gm75-j4j7
GHSA-89vp-x53w-74fx
RUSTSEC-2026-0140
RUSTSEC-2026-0189
May 18, 2026
dynoxide: DNS rebinding and cross-origin CSRF via MCP HTTP transport
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summarydynoxide's MCP HTTP transport was vulnerable to DNS rebinding via its transitive ImpactIf a user is running Reachable tools include reads ( Any data in tables that the local dynoxide instance has access to can be read, modified, or destroyed. Patchesdynoxide 0.9.13 closes both the named CVE and a related cross-origin CSRF gap:
Native MCP clients that don't send an Origin header (Claude Code, Cursor, the dynoxide CLI) are unaffected by the Origin check and continue to work. Workarounds
Resources
CreditsVulnerability identified via GitHub Dependabot alert on the transitive rmcp dependency. Fixed in
0.9.13
References Updated Jun 29, 2026 · Source: OSV.dev |
0.9.10
patch
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
0.9.9
patch
1 CVE
CVE-2026-42559
GHSA-fvh2-gm75-j4j7
GHSA-89vp-x53w-74fx
RUSTSEC-2026-0140
RUSTSEC-2026-0189
May 18, 2026
dynoxide: DNS rebinding and cross-origin CSRF via MCP HTTP transport
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summarydynoxide's MCP HTTP transport was vulnerable to DNS rebinding via its transitive ImpactIf a user is running Reachable tools include reads ( Any data in tables that the local dynoxide instance has access to can be read, modified, or destroyed. Patchesdynoxide 0.9.13 closes both the named CVE and a related cross-origin CSRF gap:
Native MCP clients that don't send an Origin header (Claude Code, Cursor, the dynoxide CLI) are unaffected by the Origin check and continue to work. Workarounds
Resources
CreditsVulnerability identified via GitHub Dependabot alert on the transitive rmcp dependency. Fixed in
0.9.13
References Updated Jun 29, 2026 · Source: OSV.dev |
0.9.9
patch
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
0.9.8
patch
1 CVE
CVE-2026-42559
GHSA-fvh2-gm75-j4j7
GHSA-89vp-x53w-74fx
RUSTSEC-2026-0140
RUSTSEC-2026-0189
May 18, 2026
dynoxide: DNS rebinding and cross-origin CSRF via MCP HTTP transport
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summarydynoxide's MCP HTTP transport was vulnerable to DNS rebinding via its transitive ImpactIf a user is running Reachable tools include reads ( Any data in tables that the local dynoxide instance has access to can be read, modified, or destroyed. Patchesdynoxide 0.9.13 closes both the named CVE and a related cross-origin CSRF gap:
Native MCP clients that don't send an Origin header (Claude Code, Cursor, the dynoxide CLI) are unaffected by the Origin check and continue to work. Workarounds
Resources
CreditsVulnerability identified via GitHub Dependabot alert on the transitive rmcp dependency. Fixed in
0.9.13
References Updated Jun 29, 2026 · Source: OSV.dev |
0.9.8
patch
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
0.9.7
patch
1 CVE
CVE-2026-42559
GHSA-fvh2-gm75-j4j7
GHSA-89vp-x53w-74fx
RUSTSEC-2026-0140
RUSTSEC-2026-0189
May 18, 2026
dynoxide: DNS rebinding and cross-origin CSRF via MCP HTTP transport
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summarydynoxide's MCP HTTP transport was vulnerable to DNS rebinding via its transitive ImpactIf a user is running Reachable tools include reads ( Any data in tables that the local dynoxide instance has access to can be read, modified, or destroyed. Patchesdynoxide 0.9.13 closes both the named CVE and a related cross-origin CSRF gap:
Native MCP clients that don't send an Origin header (Claude Code, Cursor, the dynoxide CLI) are unaffected by the Origin check and continue to work. Workarounds
Resources
CreditsVulnerability identified via GitHub Dependabot alert on the transitive rmcp dependency. Fixed in
0.9.13
References Updated Jun 29, 2026 · Source: OSV.dev |
0.9.7
patch
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
0.9.6
patch
1 CVE
CVE-2026-42559
GHSA-fvh2-gm75-j4j7
GHSA-89vp-x53w-74fx
RUSTSEC-2026-0140
RUSTSEC-2026-0189
May 18, 2026
dynoxide: DNS rebinding and cross-origin CSRF via MCP HTTP transport
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summarydynoxide's MCP HTTP transport was vulnerable to DNS rebinding via its transitive ImpactIf a user is running Reachable tools include reads ( Any data in tables that the local dynoxide instance has access to can be read, modified, or destroyed. Patchesdynoxide 0.9.13 closes both the named CVE and a related cross-origin CSRF gap:
Native MCP clients that don't send an Origin header (Claude Code, Cursor, the dynoxide CLI) are unaffected by the Origin check and continue to work. Workarounds
Resources
CreditsVulnerability identified via GitHub Dependabot alert on the transitive rmcp dependency. Fixed in
0.9.13
References Updated Jun 29, 2026 · Source: OSV.dev |
0.9.6
patch
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
0.9.5
minor
1 CVE
CVE-2026-42559
GHSA-fvh2-gm75-j4j7
GHSA-89vp-x53w-74fx
RUSTSEC-2026-0140
RUSTSEC-2026-0189
May 18, 2026
dynoxide: DNS rebinding and cross-origin CSRF via MCP HTTP transport
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summarydynoxide's MCP HTTP transport was vulnerable to DNS rebinding via its transitive ImpactIf a user is running Reachable tools include reads ( Any data in tables that the local dynoxide instance has access to can be read, modified, or destroyed. Patchesdynoxide 0.9.13 closes both the named CVE and a related cross-origin CSRF gap:
Native MCP clients that don't send an Origin header (Claude Code, Cursor, the dynoxide CLI) are unaffected by the Origin check and continue to work. Workarounds
Resources
CreditsVulnerability identified via GitHub Dependabot alert on the transitive rmcp dependency. Fixed in
0.9.13
References Updated Jun 29, 2026 · Source: OSV.dev |
0.9.5
minor
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
0.0.1
initial
|