Mcp Toolbox For Databases
12 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Mcp Toolbox For Databases, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.
Mcp Toolbox For Databases CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 1 |
| 2026-06 | 5 |
| 2026-07 | 6 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 12 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical4
- High5
- Medium1
Latest CVEs
The 12 most recently published vulnerabilities affecting Mcp Toolbox For Databases.
- CVE-2026-14541Authentication Bypass and Audience Confusion in MCP Toolbox OAuth Provider7.5
- CVE-2026-14540Server-Side Request Forgery via Unrestricted HTTP Redirection in MCP Toolbox6.1
- CVE-2026-14539Denial of Service via Unrestricted Payload Buffering in MCP Toolbox7.5
- CVE-2026-14538BigQuery Dataset Allowlist Bypass via Metadata Dry-Run in MCP Toolbox7.7
- CVE-2026-14537Authorization Bypass in MCP Toolbox Legacy HTTP Endpoints9.8
- CVE-2026-15829SQL Injection and Security Boundary Bypass in googleapis/mcp-toolbox8.1
- CVE-2026-11720Path Traversal in googleapis/mcp-toolbox HTTP Tool URL Builder9.1
- CVE-2026-11719An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement across older protocol handlers. While the 2025-11-25 protocol version handl...8.1
- CVE-2026-11718An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When the toolbox validates an opaque token via an OAuth 2...9.1
- CVE-2026-11717An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When verifying an unparsed opaque token via an OAuth 2.0 ...9.1
- CVE-2026-11624The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding attacks. Prior to the v0.25.0 release, users ...—
- CVE-2026-9739Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `allowed-hosts` flags to align with MCP security guidelines. How...—
Product grouping is registry-driven, with AI assist and human review. How it works