CVE-2026-34237
EUVD-2026-1749631.03.2026, 16:16
MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to versions 1.0.1 and 1.1.1, there is a hardcoded wildcard CORS vulnerability. This issue has been patched in versions 1.0.1 and 1.1.1.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| lfprojects | mcp_java_sdk | 𝑥 < 1.0.1 |
| lfprojects | mcp_java_sdk | 1.1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References