go

github.com/modelcontextprotocol/registry

View on go registry
10 Total advisories
10 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/modelcontextprotocol/registry is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 4.0
Go

CVE-2026-44430

MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist

LOW 3.5
Go

CVE-2026-45781

MCP Registry: OCI validator skips ownership check on upstream rate limits

MEDIUM 5.4
Go

CVE-2026-44429

MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl`

UNKNOWN
Go

CVE-2026-44427

MCP Registry has open redirect via protocol-relative path in trailing-slash middleware

MEDIUM 4.7
Go

CVE-2026-44428

MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience

UNKNOWN
Go

CVE-2026-44427

MCP Registry has open redirect via protocol-relative path in trailing-slash middleware in github.com/modelcontextprotocol/registry

UNKNOWN
Go

CVE-2026-44429

MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` in github.com/modelcontextprotocol/registry

UNKNOWN
Go

CVE-2026-44430

MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist in github.com/modelcontextprotocol/registry

UNKNOWN
Go

CVE-2026-44428

MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry

UNKNOWN
Go

CVE-2026-45781

MCP Registry: OCI validator skips ownership check on upstream rate limits in github.com/modelcontextprotocol/registry

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes