PatchSiren cyber security CVE debrief
CVE-2026-35568 modelcontextprotocol CVE debrief
The CVE-2026-35568 vulnerability is a DNS rebinding issue in the MCP Java SDK prior to version 1.0.0. This vulnerability allows an attacker to access a locally or network-private MCP server via a victim's browser that is either local or network adjacent. Consequently, the attacker can make any tool calls to the server as if they were a locally running MCP connected AI agent. The vulnerability is fixed in version 1.0.0 of the MCP Java SDK.
- Vendor
- modelcontextprotocol
- Product
- java-sdk
- CVSS
- HIGH 7.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-07
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-07
- Advisory updated
- 2026-07-24
Who should care
Organizations using the MCP Java SDK prior to version 1.0.0 should be aware of this vulnerability. Specifically, those with MCP servers that are locally or network-privately accessible may be at risk. Developers and administrators responsible for the MCP Java SDK and its deployments should take immediate action to update to version 1.0.0 or apply appropriate mitigations.
Technical summary
The MCP Java SDK, which is the official Java SDK for Model Context Protocol servers and clients, contains a DNS rebinding vulnerability prior to version 1.0.0. This vulnerability, identified as CVE-2026-35568, can be exploited by an attacker to access a locally or network-private MCP server through a victim's browser. The attacker can then make tool calls to the server as if they were a locally running MCP connected AI agent. The vulnerability is addressed and fixed in version 1.0.0 of the MCP Java SDK.
Defensive priority
High
Recommended defensive actions
- Update the MCP Java SDK to version 1.0.0 or later
- Review and restrict access to MCP servers to only necessary personnel and systems
- Implement network security measures to prevent unauthorized access to MCP servers
- Monitor for any suspicious activity related to MCP server interactions
- Perform a thorough inventory of assets using the MCP Java SDK to identify potential exposure
- Establish a change management process to ensure timely application of security patches
- Review and update incident response plans to include procedures for responding to potential exploitation of the MCP Java SDK vulnerability
Evidence notes
The CVE-2026-35568 vulnerability is confirmed to exist in the MCP Java SDK prior to version 1.0.0. The vulnerability allows for DNS rebinding attacks, enabling attackers to interact with local or network-private MCP servers. The fix in version 1.0.0 is confirmed. However, specific details about the exploitation and additional attack vectors are not provided in the available sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-35568 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-35568
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-35568 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-35568
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/modelcontextprotocol/java-sdk/releases/tag/v1.0.0
[email protected] - Release Notes
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/modelcontextprotocol/java-sdk/security/advisories/GHSA-8jxr-pr72-r468
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.