Fetching from the wire…
Security2026-08-28 · source-backed
StreamableHTTPServer.ServeHTTP and SSEServer.ServeHTTP accepted any request arriving over loopback regardless of the host it named (NVD). This one matters more than the individual server CVEs beside it because mcp-go is a widely used Go SDK, so every stdio-to-HTTP server built on it inherits the hole and a page in a browser can drive a developer's local MCP server through DNS rebinding.
Each link below shares sources, entities, or timing with this story.
PraisonAI uses MCP / Shared entities / Same source domain / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (PraisonAI uses MCP); both cover CVE, CVEs, DNS, Host; reported by the same outlet (nvd.nist.gov).
Microsoft supports MCP / Shared entities / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (Microsoft supports MCP); both cover CVE, CVEs, HTTP, MCP; overlapping topics (cves, server).
MCP uses Go SDK / Shared entities / Same source / Shared topic
Linked by a graph relationship (MCP uses Go SDK); both cover CVE, CVEs, DNS, HTTP; cite the same source (NVD).
Anthropic released MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Anthropic released MCP); both cover CVE, CVEs, HTTP, MCP; overlapping topics (cves, developer, server).
Codex CLI uses MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Codex CLI uses MCP); both cover CVE, HTTP, MCP; overlapping topics (header, request, server).
Anthropic released MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Anthropic released MCP); both cover CVE, CVEs, MCP; overlapping topics (cves, server).
Windsurf uses MCP / Shared entities / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (Windsurf uses MCP); both cover CVE, CVEs; overlapping topics (browser, cves, developer).
OpenAI supports MCP / Shared entities / Earlier coverage / Tension
Linked by a graph relationship (OpenAI supports MCP); both cover CVE, HTTP, MCP; earlier CVE coverage from 2026-07-23.