CVE-2026-34237: Lfprojects Mcp Java SDK
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to versions 0.83.0, 1.0.1, and 1.1.1, there is a hardcoded wildcard CORS vulnerability. This issue has been patched in versions 0.83.0, 1.0.1, and 1.1.1.
Affected products
- Lfprojects Mcp Java SDK: before 1.0.1 (fixed in 1.0.1); version 1.1.0 only
Published 2026-03-31. Last modified 2026-07-24.