THREAT OPS › Threat News › [NVD] CVE-2026-14540 (MEDIUM 6.1) — A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled parameters, the underlying HTTP client (intern
[NVD] CVE-2026-14540 (MEDIUM 6.1) — A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled parameters, the underlying HTTP client (intern
CVE-2026-14540 CVSS: 6.1 MEDIUM Published: 2026-07-31T02:16:29.060
A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled parameters, the underlying HTTP client (internal/sources/http/http.go) fails to safely regulate re
Indicators of compromise
- CVE-2026-14540cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-14540