CVE-2026-16971
The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks.
CVSS
5.9
Medio
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 30 jul 2026 · Última mod.: 30 jul 2026 · CWE-770
Sin historial EPSS suficiente todavía.
The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-183625.9 MED—
——0The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks.5hCVE-2026-674377.5 ALT—
——0OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login handler stores per-login state in the registeredStates map on every /oauth/login request without expiring, deleting, or bounding entries, allowing an unauthenticated attacker to exhaust memory and cause a denial of service. This issue is fixed in version 3000.17.0.18hCVE-2026-674327.5 ALT—
——0MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem reads and parses an entire JSON-RPC POST body without a size limit, allowing an unauthenticated remote attacker to exhaust process memory. This issue is fixed in version 0.23.0.19hCVE-2026-674305.3 MED—
——0MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not expire sessions by default, so repeated initialize requests retain unbounded ServerSession objects and can exhaust process memory. This issue is fixed in version 0.23.0.19hCVE-2026-631196.2 MED—
——0MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StdioTransport and MCP::Client::Stdio in the mcp gem use IO#gets without a byte limit, allowing a peer that sends data without a newline to exhaust process memory. This issue is fixed in version 0.23.0.19hCVE-2026-159757.5 ALT—
——0GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to insufficient resource throttling when processing merge request discussions.19h