RE: DevDefender Security Digest — 2026-09-16

Sending you the most important threats and vulnerabilities that threaten developers. Your team is resourceful, and they should have the information to adapt to today's threats.

1.CVE-2026-63127 | Model Context Protocol RMCP SDK up to 1.x OAuth Implementation auth.rs discover_oauth_server_via_resource_metadata improper authorization
VulDB Recent Entries · 2026-09-16
A vulnerability classified as problematic was found in Model Context Protocol RMCP SDK up to 1.x. This impacts the function discover_oauth_server_via_resource_metadata of the file crates/rmcp/src/tran…
mcpmodel context protocol
2.[mysql-mcp-server] MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)
GitHub Advisory DB — PyPI · 2026-09-11
pypimcp

Keep your team informed, daily

Stay ahead of threats targeting developers. Get curated security intelligence delivered to your whole team — AI agent exploits, supply chain attacks, CI/CD vulnerabilities, and more.