{"id":"GHSA-hv2w-8mjj-jw22","summary":"MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)","details":"### Summary\n\n**Hardcoded Wildcard CORS (Access-Control-Allow-Origin: * )**\n\n- https://github.com/modelcontextprotocol/java-sdk/blob/main/mcp-core/src/main/java/io/modelcontextprotocol/server/transport/HttpServletSseServerTransportProvider.java#L289\n- https://github.com/modelcontextprotocol/java-sdk/blob/main/mcp-core/src/main/java/io/modelcontextprotocol/server/transport/HttpServletStreamableServerTransportProvider.java#L525\n\n### Attack Scenario\nAn attacker-controlled web page instructs the victim's browser to open GET https://internal-mcp-server/sse. Because Access-Control-Allow-Origin: * allows cross-origin SSE reads, the attacker's page receives the endpoint event — which contains the session ID. The attacker can then POST to that endpoint from their page using the victim's browser as a relay.\n\n### Comparison with python-sdk\nNo Access-Control-Allow-Origin header is emitted by either Python transport. The browser's default same-origin policy remains in full effect.\nhttps://github.com/modelcontextprotocol/python-sdk/blob/main/src/mcp/server/sse.py\nhttps://github.com/modelcontextprotocol/python-sdk/blob/main/src/mcp/server/streamable_http.py\n\n### Recommendation\nIn the SDK, the transport layer should not own CORS policy. Server implementors who need cross-origin access can add a CORS filter at the servlet filter or Spring Security layer.\n\n### Reference\n\n- https://cheatsheetseries.owasp.org/cheatsheets/HTTP_Headers_Cheat_Sheet.html#access-control-allow-origin","aliases":["CVE-2026-34237"],"modified":"2026-09-10T03:50:39.742363136Z","published":"2026-03-30T17:26:44Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-03-30T17:26:44Z","nvd_published_at":"2026-03-31T16:16:32Z","cwe_ids":["CWE-942"]},"references":[{"type":"WEB","url":"https://github.com/modelcontextprotocol/java-sdk/security/advisories/GHSA-hv2w-8mjj-jw22"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34237"},{"type":"WEB","url":"https://cheatsheetseries.owasp.org/cheatsheets/HTTP_Headers_Cheat_Sheet.html#access-control-allow-origin"},{"type":"PACKAGE","url":"https://github.com/modelcontextprotocol/java-sdk"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/java-sdk/blob/main/mcp-core/src/main/java/io/modelcontextprotocol/server/transport/HttpServletSseServerTransportProvider.java#L289"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/java-sdk/blob/main/mcp-core/src/main/java/io/modelcontextprotocol/server/transport/HttpServletStreamableServerTransportProvider.java#L525"}],"affected":[{"package":{"name":"io.modelcontextprotocol.sdk:mcp-core","ecosystem":"Maven","purl":"pkg:maven/io.modelcontextprotocol.sdk/mcp-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"1.0.1"}]}],"versions":["1.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-hv2w-8mjj-jw22/GHSA-hv2w-8mjj-jw22.json"}},{"package":{"name":"io.modelcontextprotocol.sdk:mcp-core","ecosystem":"Maven","purl":"pkg:maven/io.modelcontextprotocol.sdk/mcp-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.1.0"},{"fixed":"1.1.1"}]}],"versions":["1.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-hv2w-8mjj-jw22/GHSA-hv2w-8mjj-jw22.json"}},{"package":{"name":"io.modelcontextprotocol.sdk:mcp-core","ecosystem":"Maven","purl":"pkg:maven/io.modelcontextprotocol.sdk/mcp-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.18.3"}]}],"versions":["0.13.0","0.13.1","0.14.0","0.14.1","0.15.0","0.16.0","0.17.0","0.17.1","0.17.2","0.18.0","0.18.1","0.18.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-hv2w-8mjj-jw22/GHSA-hv2w-8mjj-jw22.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}