Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 29 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google mcp Toolbox For Databases |
|
| Vendors & Products |
Google
Google mcp Toolbox For Databases |
Thu, 28 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | DNS Rebinding via SSE Causing CORS Bypass in MCP Toolbox for Databases |
Wed, 27 May 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `allowed-hosts` flags to align with MCP security guidelines. However, the hardcoded `Access-Control-Allow-Origin: *` header in the SSE initialization handler was inadvertently retained. This vulnerability specifically impacts users connecting via Toolbox using SSE under specification v2024-11-05. | |
| Weaknesses | CWE-942 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2026-05-28T13:20:43.816Z
Reserved: 2026-05-27T17:31:41.604Z
Link: CVE-2026-9739
Updated: 2026-05-28T13:19:59.632Z
Status : Awaiting Analysis
Published: 2026-05-27T23:16:48.573
Modified: 2026-06-17T11:05:36.330
Link: CVE-2026-9739
No data.
OpenCVE Enrichment
Updated: 2026-05-29T15:49:47Z