CVE-2026-35568 is a DNS rebinding vulnerability in MCP Java SDK versions prior to 1.0.0 that enables attackers to access locally or network-private MCP servers through a victim's browser. An attacker exploiting this flaw can execute arbitrary tool calls against vulnerable servers as if they were legitimately connected AI agents, affecting organizations using the official Java SDK for Model Context Protocol implementations. The vulnerability presents a medium severity risk with a CVSS score of 5.7, requiring adjacent network access and user interaction but posing no confidentiality risk while carrying high integrity impact. The attack has low complexity and requires no special privileges, making it relatively straightforward to execute once proximity to the target network is achieved. The vulnerability is not currently being actively exploited, as indicated by its absence from CISA's Known Exploited Vulnerabilities catalog and its inactive status on the Hot List. The EPSS score of 0.00017 reflects minimal real-world exploitation activity, though organizations running MCP Java SDK versions before 1.0.0 should apply the available patch to eliminate this attack vector.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.0CPE matchmatch criteria | cpe:2.3:a:lfprojects:mcp_java_sdk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.