MEDIUM5.4CVE-2026-44429MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry from 0, < 1.7.7
MEDIUM5.4CVE-2026-44429MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry from 0, < 1.7.7
MEDIUM4.7CVE-2026-44428MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry from 0, < 1.7.6
MEDIUM4.7MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry
from 0, < 1.7.6
MEDIUM4.0MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry
from 0, < 1.7.7
MEDIUM4.0MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry
from 0, < 1.7.7
LOW3.5MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry
from 0, < 1.7.9
LOW3.5MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry
from 0, < 1.7.9
—MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry
>= 1.1.0, < 1.7.5
—MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry
>= 1.1.0, < 1.7.5