Security Flaw in mcp-security Framework for Spring AI Affects OAuth Implementations
CVE-2026-45609

7.2HIGH

Key Information:

Vendor
CVE Published:
29 May 2026

What is CVE-2026-45609?

The mcp-security framework for Spring AI is vulnerable due to a failure to enforce SSRF mitigations, as defined in the Model Context Protocol specifications. This issue arises when untrusted URLs are processed for OAuth-related discovery and metadata without proper verification, potentially allowing attackers to exploit the system. Notably, the risk is heightened for installations with Dynamic Client Registration (DCR) enabled. Users are encouraged to update to version 0.1.9 or later to mitigate this risk.

Affected Version(s)

mcp-security < 0.1.9

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.