CVE-2026-50027
- EPSS 0.5%
- Veröffentlicht 14.08.2026 19:17:18
- Zuletzt bearbeitet 17.08.2026 16:16:57
mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even when the server is configured with an API key (MC...
CVE-2026-49291
- EPSS 0.49%
- Veröffentlicht 19.06.2026 17:59:48
- Zuletzt bearbeitet 23.06.2026 15:59:21
mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope for all requests, then dispatches `tools/call` directly to handlers that include mu...
CVE-2026-33010
- EPSS 0.39%
- Veröffentlicht 20.03.2026 18:33:39
- Zuletzt bearbeitet 14.04.2026 18:12:23
mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.25.1, when the HTTP server is enabled (MCP_HTTP_ENABLED=true), the application configures FastAPI's CORSMiddleware with allow_origins=['*'], allow_creden...
CVE-2026-29787
- EPSS 0.37%
- Veröffentlicht 07.03.2026 15:34:46
- Zuletzt bearbeitet 11.03.2026 20:39:21
mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.21.0, the /api/health/detailed endpoint returns detailed system information including OS version, Python version, CPU count, memory totals, disk usage, a...