rmcp
crates.io4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting rmcppage 1 of 1
- CVE-2026-42559HIGHCVSS 8.8EG 8.8✓ Fixed in 1.4.02026-05-14
RMCP is an official Rust SDK for the Model Context Protocol. Prior to version 1.4.0, the rmcp crate's Streamable HTTP server transport (crates/rmcp/src/transport/streamable_http_server/) did not validate the incoming Host header. This allo…
- CVE-2026-63127HIGHCVSS 8.2EG 8.2✓ Fixed in 2.0.02026-09-16
RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crates/rmcp/src/transport/auth.rs omits the RFC 9728 resource field from ResourceServerMetadata and allows discover_oauth…
- CVE-2026-63128HIGHCVSS 7.5EG 7.5✓ Fixed in 2.0.02026-09-16
RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP server in crates/rmcp/src/transport/streamable_http_server/tower.rs allows an unauthenticated client to send a well-form…
- CVE-2026-64684MEDIUMCVSS 6.8EG 6.8✓ Fixed in 2.1.02026-09-16
RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_client with reqwest's…
Check whether rmcp is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for rmcp CVEs against the assets you own.
Start Free Scan →