github.com/modelcontextprotocol/registry
A community driven registry service for Model Context Protocol (MCP) servers.
Activity
- Latest release
- 1mo ago
- Total releases
- 36
- Cadence
- ~daily
- Last 12 months
- 27
Reach
- Stars
- 7.1k
Details
- First release
- Sep 08, 2025
| Version | Released | |
|---|---|---|
v1.8.1
patch
|
v1.8.1
patch
Dependencies (21)
+ 13 more |
|
v1.8.0
minor
|
v1.8.0
minor
Dependencies (21)
+ 13 more |
|
v1.7.9
patch
|
v1.7.9
patch
Dependencies (21)
+ 13 more |
|
v1.7.8
patch
1 CVE
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.7.8
patch
Dependencies (21)
+ 13 more |
|
v1.7.7
patch
1 CVE
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.7.7
patch
Dependencies (21)
+ 13 more |
|
v1.7.6
patch
3 CVEs
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.7.6
patch
Dependencies (21)
+ 13 more |
|
v1.7.5
patch
4 CVEs
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.7.5
patch
Dependencies (21)
+ 13 more |
|
v1.7.4
patch
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.7.4
patch
Dependencies (21)
+ 13 more |
|
v1.7.3
patch
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.7.3
patch
Dependencies (21)
+ 13 more |
|
v1.7.2
patch
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.7.2
patch
Dependencies (21)
+ 13 more |
|
v1.7.1
patch
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.7.1
patch
Dependencies (21)
+ 13 more |
|
v1.7.0
minor
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.7.0
minor
Dependencies (21)
+ 13 more |
|
v1.6.0
minor
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.6.0
minor
Dependencies (21)
+ 13 more |
|
v1.5.0
minor
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.5.0
minor
Dependencies (22)
+ 14 more |
|
v1.4.1
patch
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.4.1
patch
Dependencies (21)
+ 13 more |
|
v1.4.0
minor
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.4.0
minor
Dependencies (21)
+ 13 more |
|
v1.3.10
patch
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.3.10
patch
Dependencies (21)
+ 13 more |
|
v1.3.9
patch
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.3.9
patch
Dependencies (21)
+ 13 more |
|
v1.3.8
patch
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.3.8
patch
Dependencies (21)
+ 13 more |
|
v1.3.7
patch
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.3.7
patch
Dependencies (21)
+ 13 more |
|
v1.3.6
patch
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.3.6
patch
Dependencies (21)
+ 13 more |
|
v1.3.5
patch
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.3.5
patch
Dependencies (17)
+ 9 more |
|
v1.3.4
patch
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.3.4
patch
Dependencies (17)
+ 9 more |
|
v1.3.3
patch
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.3.3
patch
Dependencies (16)
+ 8 more |
|
v1.3.2
patch
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.3.2
patch
Dependencies (16)
+ 8 more |
|
v1.3.1
patch
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.3.1
patch
Dependencies (16)
+ 8 more |
|
v1.3.0
minor
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.3.0
minor
Dependencies (16)
+ 8 more |
|
v1.2.3
patch
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.2.3
patch
Dependencies (16)
+ 8 more |
|
v1.2.2
patch
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.2.2
patch
Dependencies (16)
+ 8 more |
|
v1.2.1
patch
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.2.1
patch
Dependencies (16)
+ 8 more |
|
v1.2.0
minor
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.2.0
minor
Dependencies (16)
+ 8 more |
|
v1.1.0
minor
5 CVEs
CVE-2026-44427
GO-2026-5658
GHSA-v8vw-gw5j-w7m6
Jun 25, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry Fixed in
1.7.5
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.1.0
minor
Dependencies (16)
+ 8 more |
|
v1.0.0
major
4 CVEs
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v1.0.0
major
Dependencies (17)
+ 9 more |
|
v0.0.3
patch
4 CVEs
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v0.0.3
patch
Dependencies (17)
+ 9 more |
|
v0.0.2
patch
4 CVEs
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v0.0.2
patch
Dependencies (17)
+ 9 more |
|
v0.0.1
initial
4 CVEs
CVE-2026-44429
GO-2026-5637
GHSA-rqv2-m695-f8j4
Jun 25, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44430
GO-2026-5607
GHSA-r48c-v28r-pf6v
Jun 25, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry Fixed in
1.7.7
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44428
GO-2026-5273
GHSA-95c3-6vvw-4mrq
Jun 25, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry Fixed in
1.7.6
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45781
GO-2026-5008
GHSA-2v5f-5r6w-p67r
May 20, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry Fixed in
1.7.9
References Updated May 21, 2026 · Source: OSV.dev |
v0.0.1
initial
Dependencies (17)
+ 9 more |