Model Context Protocol Java SDK Hardcoded Wildcard CORS Vulnerability

Vulnerability

A hardcoded wildcard Cross-Origin Resource Sharing (CORS) vulnerability has been identified in the Model Context Protocol (MCP) Java SDK, specifically in versions prior to 1.0.1 and 1.1.1. This vulnerability allows any origin to access server-sent events (SSE) from the affected server, potentially exposing sensitive information such as session IDs.

Impact

Exploitation of this vulnerability allows for unauthorized cross-origin access to server-sent events, enabling an attacker to intercept session IDs and relay messages through the victim's browser.

Remediation

Users can update to MCP Java SDK versions 1.0.1 or 1.1.1 to address this vulnerability. For additional CORS management, server implementors can add a CORS filter at the servlet filter or Spring Security layer.

Added: Mar 31, 2026, 4:35 PM
Updated: Mar 31, 2026, 4:35 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.2
exploitability
6.9
remediation
0.0
relevance
5.0
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.