THREAT OPS › Threat News › [NVD] CVE-2026-64684 (MEDIUM 6.8) — RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_client with reqwest's automatic redirect policy and applies ca
[NVD] CVE-2026-64684 (MEDIUM 6.8) — RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_client with reqwest's automatic redirect policy and applies ca
CVE-2026-64684 CVSS: 6.8 MEDIUM Published: 2026-09-16T22:17:04.577
RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_client with reqwest's automatic redirect policy and applies caller-supplied values from StreamableHttpClientTransp
Indicators of compromise
- CVE-2026-64684cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-64684