MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to versions 0.83.0, 1.0.1, and 1.1.1, there is a hardcoded wildcard CORS vulnerability. This issue has been patched in versions 0.83.0, 1.0.1, and 1.1.1.
References
Configurations
Configuration 1 (hide)
|
History
09 Jun 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to versions 0.83.0, 1.0.1, and 1.1.1, there is a hardcoded wildcard CORS vulnerability. This issue has been patched in versions 0.83.0, 1.0.1, and 1.1.1. |
03 Apr 2026, 14:29
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:lfprojects:mcp_java_sdk:*:*:*:*:*:*:*:* cpe:2.3:a:lfprojects:mcp_java_sdk:1.1.0:*:*:*:*:*:*:* |
|
| References | () https://github.com/modelcontextprotocol/java-sdk/blob/main/mcp-core/src/main/java/io/modelcontextprotocol/server/transport/HttpServletSseServerTransportProvider.java#L289 - Patch | |
| References | () https://github.com/modelcontextprotocol/java-sdk/blob/main/mcp-core/src/main/java/io/modelcontextprotocol/server/transport/HttpServletStreamableServerTransportProvider.java#L525 - Patch | |
| References | () https://github.com/modelcontextprotocol/java-sdk/security/advisories/GHSA-hv2w-8mjj-jw22 - Mitigation, Vendor Advisory | |
| First Time |
Lfprojects mcp Java Sdk
Lfprojects |
31 Mar 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-31 16:16
Updated : 2026-06-17 10:38
NVD link : CVE-2026-34237
Mitre link : CVE-2026-34237
CVE.ORG link : CVE-2026-34237
JSON object : View
Products Affected
lfprojects
- mcp_java_sdk
CWE
CWE-942
Permissive Cross-domain Policy with Untrusted Domains
