THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-64684 (MEDIUM 6.8) — RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_client with reqwest's automatic redirect policy and applies ca

[NVD] CVE-2026-64684 (MEDIUM 6.8) — RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_client with reqwest's automatic redirect policy and applies ca

mednvdPublished 2026-09-16

CVE-2026-64684 CVSS: 6.8 MEDIUM Published: 2026-09-16T22:17:04.577

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_client with reqwest's automatic redirect policy and applies caller-supplied values from StreamableHttpClientTransp

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-64684