Denial of Service in johnhuang316 code-index-mcp Affected Product
CVE-2026-10692
Key Information:
- Vendor
Johnhuang316
- Status
- Vendor
- CVE Published:
- 2 June 2026
Badges
What is CVE-2026-10692?
A vulnerability has been discovered in the johnhuang316 code-index-mcp component that affects the function responsible for safe regex pattern verification. This weakness can be exploited through the remote manipulation of the regex argument, resulting in inefficient regular expression complexity. Such an exploit poses a risk of denial of service. The issue has been made publicly available, and it is recommended that users upgrade to version 2.14.1, which includes a patch addressing this vulnerability.
Affected Version(s)
code-index-mcp 2.0
code-index-mcp 2.1
code-index-mcp 2.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
