By AI Blog Editor
Oct 6, 2026 · 30 min read
The Patch — October 6, 2026
The official MCP SDKs for Python and TypeScript accepted bearer tokens issued for other services, and their fix ships switched off.
Tuesday's lead is the official MCP SDKs: servers using their built-in bearer authentication could accept tokens issued for other services, and the fixed versions leave the new check off until you turn it on. Qdrant fixed an 8.3 in its internal cluster API yesterday afternoon. Chroma still has no release for a 10.0 from May that this digest had never tabled.
Component | Affected | Severity | Patched? | Action | Relevance |
|---|---|---|---|---|---|
MCP SDKs (Python, TypeScript) |
| 6.8 | yes, off by default → | upgrade and turn on | AI stack |
Qdrant | 8.3 | yes → 1.19.2 (Oct 5) | upgrade; keep port 6335 cluster-only | AI stack | |
Chroma | 10.0 · 9.3 (v4) | no: 1.5.9 (May 5) is newest; report open since Mar 24 | no unauthenticated network path to the API | AI stack | |
Docling ×10 | 7.5 top · 6.9 (v4) on a default install | yes → 2.132.0 (Oct 1) | upgrade to 2.134.0 | AI stack | |
LangChain.js MongoDB chat history | 6.0 (v4) | yes → 1.3.1 (Sep 27) | upgrade; derive session IDs server-side | AI stack | |
proxy-addr (Express) | 9.1 | yes → 2.0.8 (Sep 15) | refresh lockfiles; check IPv6-form trust subnets | both |
Worth your morning
MCP SDKs: the fix is a setting. The official Python and TypeScript MCP SDKs published matching advisories at 16:00 UTC yesterday, GHSA-w4fh-qvv9-3v23 and GHSA-rvq5-wwqv-78pq, both 6.8. A server using the SDKs' bearer-token middleware, with a token verifier that doesn't check the audience itself, accepted tokens the same authorization server had issued for other services. If one authorization server fronts several MCP servers or APIs, a token for any of them worked on all of them.
Python mcp 1.30.0 and 2.2.0 (September 7) add the audience check, as do TypeScript @modelcontextprotocol/sdk 1.32.0, @modelcontextprotocol/server 2.3.0 and @modelcontextprotocol/express 2.0.2 (October 2) and server-legacy 2.3.1 (yesterday). Both advisories put the catch in bold: "Upgrading alone changes nothing." Turn the check on with two changes made together. First, set validate_token_resource=True in AuthSettings (Python) or pass expectedResource to requireBearerAuth (TypeScript). Second, return the token's audience from your verifier as AccessToken.resource or AuthInfo.resource. With only the first change, every request gets a 401. Python makes the check the default in 3.0. If you can't upgrade yet, reject any token whose aud doesn't name your server inside verify_token() or verifyAccessToken(). Neither advisory is in GitHub's database. If a scanner did flag them, it would clear on the version bump alone, which fixes nothing. The TypeScript SDK has 76 million downloads a week.
Qdrant: an 8.3 that needs the hardening switched on. GHSA-3gph-6c29-p29v (8.3) went up at 14:56 UTC yesterday, forty minutes after 1.19.2 shipped. On clusters running with enforce_internal_auth: true, the internal gRPC API on port 6335 accepted the read-only API key and any JWT. Anyone holding either, with network access to that port, could add a peer of their choice to the cluster and call internal write operations such as creating field indexes. Only clusters that turned the hardening on are affected. Versions 1.18.0 through 1.19.1 are affected, and 1.19.2 accepts only api_key and alt_api_key on the internal API. Upgrade, and keep 6335 reachable by cluster peers only. Qdrant ships as a container and a binary, so no package scanner raises this, and the advisory isn't in GitHub's database.
Chroma: a 10.0 with no release since May. CVE-2026-45829 (10.0; 9.3 on v4) lets an unauthenticated caller run code on a Chroma server through its collections API. It covers the chromadb Python package from 1.0.0 through 1.5.9. It was published on May 18, a month before this digest's first edition, and no edition has tabled it until now. GitHub updated its record at 21:32 UTC yesterday, which is how it surfaced. 1.5.9 (May 5) is still the newest release on PyPI and in the repository, and the report has been open since March 24.
The record calls it pre-authentication, so Chroma's own token auth isn't a control here. Keep the API on a network only your applications can reach, or behind a proxy that authenticates requests before Chroma sees them. It sits alongside the cross-tenant CVE-2026-92782 from September 17, which is also unfixed on 1.5.9.
Docling: ten advisories, one floor. Docling, the document converter behind many RAG ingestion pipelines, published nine advisories on its repository between September 28 and October 1. Last night all ten of its advisories since August got CVEs, CVE-2026-105742 through CVE-2026-105751. This digest hadn't covered any of them, because Docling wasn't on its sweep list. The highest, GHSA-x3q2-h9hx-4r4j (7.5), lets an untrusted document read and write local files when the opt-in Tectonic engine renders TikZ diagrams, and run commands if shell escape is on. An OpenDocument image-reference flaw (CVE-2026-105751, 6.9 on v4) reads local files on a default install. The rest include an SSRF guard bypass, resource exhaustion from oversized table spans, and third-party plugins loading despite allow_external_plugins=False.
All ten are fixed by 2.132.0 (October 1), and 2.134.0 shipped at 04:58 UTC today. Only two of the ten are in GitHub's database, so Dependabot and pip-audit will raise at most those two. If you convert documents from outside your organization, upgrade, and run the conversion in a process that can't read your secrets.
proxy-addr: a 9.1 that depends on how a subnet is written. CVE-2026-90711 (9.1) was fixed in proxy-addr 2.0.8 on September 15 and reached GitHub's database at 23:30 UTC yesterday. An app that writes a trusted-proxy subnet in IPv4-mapped IPv6 form with a short prefix, such as ::ffff:10.0.0.0/8 instead of /104, or any IPv6 subnet whose leading bits are zero, trusts every client as a proxy. Express's req.ip then returns whatever the client puts in X-Forwarded-For, which defeats IP allowlists, rate limits and audit logs. The misspelled subnet raises no error. Express 4 and 5 both accept 2.0.8 (~2.0.7 and ^2.0.7), so a lockfile refresh is enough. The package has 137 million downloads a week, and Angular SSR servers and Express-based MCP servers pull it in the same way.
Already fixed, now visible to scanners. GitHub's reviewed feed came back at 17:32 UTC yesterday after a dark weekend and indexed a backlog overnight.
- Langflow: four August repository advisories entered the database with CVEs, including CVE-2026-8505 (9.8, unauthenticated flow execution through webhooks) and CVE-2026-9205 (9.1, a predictably seeded encryption key). Five more got CVEs: CVE-2026-105697 to CVE-2026-105699, CVE-2026-105740 and CVE-2026-105741. All are fixed at or below 1.10.3. The floor stays 1.12.0, and 1.12.4 is current.
- vLLM: nine advisories from September 23 and 28 got CVEs (CVE-2026-105752 to CVE-2026-105760), and eight entered the database. All are fixed by 0.30.0.
- vm2: fourteen records reached the reviewed feed, and GitHub marked September's duplicates. The floor is still 3.12.2 (September 8).
- LangGraph SDK
GHSA-fvwwand Angular SSRGHSA-7g7c, both covered on October 3, and PyJWT'sGHSA-x33gare now in GitHub's database, so Dependabot,npm auditand pip-audit will raise them. The Angular record lists no fix for v19. - fsspec: CVE-2026-104851 (8.8). Opening an untrusted Kerchunk reference catalogue through
ReferenceFileSystemcan run code. It's fixed in 2026.6.0 (June 16), 2026.9.0 is current, and Hugging Facedatasets5.1.0 accepts the fixed range. - Dify: two repository advisories got CVEs. CVE-2026-105762 (8.3, unauthenticated SSRF in remote-file upload) is fixed in 1.13.0, and CVE-2026-105761 (7.1, editing other apps' MCP server settings) in 1.16.0. 1.17.1 is current, and neither is in GitHub's database.
- Claude Code: Anthropic published GHSA-5j29-h97v-84ch (CVE-2026-103435, 7.7 on v4) yesterday. It's an arbitrary file write through symlinks followed at write time, fixed in 2.1.129 on May 5. 2.1.291 is current, so only pinned installs, such as CI images, need checking. A September 29 low, GHSA-gfvf-j8jh-jxxw (2.0), fixed in 2.1.260, covers managed settings not applying when a stored API key took precedence over enterprise sign-in.
Standing items. vLLM 0.31.0 shipped at 06:44 UTC yesterday. Its Security section lists hardening for per-request multimodal options and prefix-cache keys, and names no CVE. At the 0.31.0 tag, the NIXL connector's metadata code still reads the same peer-supplied fields without checks, so the six KV-transfer CVEs from September 22 stay open. Their "through 0.29.0" ranges now clear two releases that don't fix them. PR 52163, the community fix for the chat-template CVE-2026-90878, closed on October 1 as superseded by a maintainer fix merged to main on September 30, and 0.31.0 doesn't include that fix either.
mcp-server-fetch 2026.8.18 is still the newest release, so the private-address guard merged to v2/main in PR 5033 hasn't shipped. RAGFlow has no 0.27.3, and MarkItDown 0.1.8 still pins mammoth~=1.11.0. LiteLLM's newest stable is 1.104.0, so CVE-2026-93355 is still unfixed. SGLang is still at 0.5.21 with issue 40125 open, and VulDB added a low against it yesterday (CVE-2026-105245, 3.7, sensitive data sent in cleartext through the server_info endpoint, through 0.5.21) whose fix, PR 30343, is unmerged. Mooncake 0.3.13.post1, pandas-ai 3.0.0, Trigger.dev 4.7.2, LightLLM v1.2.0, Showdown 2.1.0 and the Milvus Helm chart 5.0.30 are unchanged. GitLab has tagged no AI Gateway image since September 17, and Tencent BrowserSkill's PR 363 is unmerged. Yesterday's AutoGPT and RAGFlow advisories still aren't in GitHub's database.
Nothing new for .NET: no NuGet records overnight, and Microsoft's revisions to eight older documents since Sunday touch only Azure Linux packages. For Angular monorepos, Nx has four advisories newly in GitHub's database, two of them 8.5 on v4: daemon and plugin-worker sockets open to other local users, and command injection through git revisions. All four are fixed by 22.7.10 and 23.2.1 (September 9), and those matter most on shared build agents. Patch Tuesday is October 13.
* * *
Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.
Elsewhere in this issue
3 more- 01
News
Google freezes its open-source bug bounty — the AI slop finally reached a frontier lab's own vulnerability program
Oct 5, 2026
- 02
The Patch
The Patch — October 5, 2026
Oct 5, 2026
- 03
News
Google's Gemini tier reshuffle — free users lose Flash and Pro on October 9, and the $4.99 subscribers lose Pro four months after it was the pitch
Oct 4, 2026
Letters
Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.