CVE-2026-35568
MCP Java-SDK has a DNS Rebinding Vulnerability
Description
MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to 1.0.0, the java-sdk contains a DNS rebinding vulnerability. This vulnerability allows an attacker to access a locally or network-private java-sdk MCP server via a victims browser that is either local, or network adjacent. This allows an attacker to make any tool call to the server as if they were a locally running MCP connected AI agent. This vulnerability is fixed in 1.0.0.
INFO
Published Date :
April 7, 2026, 10:16 p.m.
Last Modified :
July 24, 2026, 9:10 p.m.
Remotely Exploit :
Yes !
Source :
[email protected]
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | |||||
| CVSS 3.1 | MEDIUM | [email protected] | ||||
| CVSS 4.0 | HIGH | [email protected] |
Solution
- Update MCP Java SDK to version 1.0.0 or later.
- Ensure proper network access controls are in place.
Public PoC/Exploit Available at Github
CVE-2026-35568 has a 4 public
PoC/Exploit available at Github.
Go to the Public Exploits tab to see the list.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-35568.
| URL | Resource |
|---|---|
| https://github.com/modelcontextprotocol/java-sdk/releases/tag/v1.0.0 | Release Notes |
| https://github.com/modelcontextprotocol/java-sdk/security/advisories/GHSA-8jxr-pr72-r468 | Vendor Advisory |
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-35568 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-35568
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Production security middleware for MCP servers - DNS rebinding protection, CORS guard, tool filtering
Python TypeScript
Self-hosted MCP server for citation verification, integrity, and discovery across Crossref, PubMed, OpenAlex, Semantic Scholar, and arXiv. Companion to manuscript-audit and advanced-researcher.
Python Shell
The Project shares all information on MCP related CVE's published
mcp mcp-security mcp-cve
Static scanner for MCP-connected AI agent pipelines — 225 rules across 11 categories, 12 compliance frameworks, OWASP Agentic 10/10 + MCP 10/10, GitHub Action, SARIF, public CVE-to-rule ledger.
ai-agent ai-security claude-code github-action mcp mcp-security owasp sarif scanner security supply-chain-security tool-poisoning ai-agent-security ai-safety security-scanner static-analysis
Python Dockerfile Shell TypeScript HTML Makefile
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-35568 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-35568 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Translated by [email protected]
Jul. 24, 2026
Action Type Old Value New Value Added Translation Title: java-sdk de modelcontextprotocol, Description: MCP Java SDK es el SDK oficial de Java para servidores y clientes de Model Context Protocol. Antes de la 1.0.0, el java-sdk contiene una vulnerabilidad de reenlace de DNS. Esta vulnerabilidad permite a un atacante acceder a un servidor MCP java-sdk local o privado de red a través del navegador de una víctima que es local o adyacente a la red. Esto permite a un atacante realizar cualquier llamada de herramienta al servidor como si fuera un agente de IA conectado a MCP ejecutándose localmente. Esta vulnerabilidad está corregida en la 1.0.0. -
CVE Modified by [email protected]
Jun. 17, 2026
Action Type Old Value New Value Added Affected [{'vendor': 'modelcontextprotocol', 'product': 'java-sdk', 'versions': [{'status': 'affected', 'version': '< 1.0.0'}]}] -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jun. 17, 2026
Action Type Old Value New Value Added SSVC {'id': 'CVE-2026-35568', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-04-08T15:43:13.122284Z'} -
Initial Analysis by [email protected]
Apr. 14, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N Added CPE Configuration OR *cpe:2.3:a:lfprojects:mcp_java_sdk:*:*:*:*:*:*:*:* versions up to (excluding) 1.0.0 Added Reference Type GitHub, Inc.: https://github.com/modelcontextprotocol/java-sdk/releases/tag/v1.0.0 Types: Release Notes Added Reference Type GitHub, Inc.: https://github.com/modelcontextprotocol/java-sdk/security/advisories/GHSA-8jxr-pr72-r468 Types: Vendor Advisory -
New CVE Received by [email protected]
Apr. 07, 2026
Action Type Old Value New Value Added Description MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to 1.0.0, the java-sdk contains a DNS rebinding vulnerability. This vulnerability allows an attacker to access a locally or network-private java-sdk MCP server via a victims browser that is either local, or network adjacent. This allows an attacker to make any tool call to the server as if they were a locally running MCP connected AI agent. This vulnerability is fixed in 1.0.0. Added CVSS V4.0 AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Added CWE CWE-346 Added Reference https://github.com/modelcontextprotocol/java-sdk/releases/tag/v1.0.0 Added Reference https://github.com/modelcontextprotocol/java-sdk/security/advisories/GHSA-8jxr-pr72-r468