CVE-2025-56404: MariaDB Model Context Protocol

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitive information via the SSE service as the SSE service lacks user validation.

Affected products

  • MariaDB Model Context Protocol: version 0.1.0 only

Published 2025-09-10. Last modified 2026-06-17.