CVE-2026-50027 was published to the National Vulnerability Database on 2026-08-14 with a CVSS score of 9.8, covering mcp-memory-service versions before 10.67.1. All HTTP routes under /api/documents/* were served without authentication even when the server was configured with an API key or OAuth, letting an unauthenticated remote attacker write, read, and delete stored memory content. The underlying GitHub advisory was published 2026-07-02. The project's GitHub repository and maintainer account returned 404 when checked on 2026-08-14, while PyPI releases continued through 11.8.0 on 2026-08-09.
Ranked by Adoption Index v1 (measured public adoption, not a quality verdict) · snapshot 2026-08-14 · Movers: io.github.YawLabs/postgres-mcp up 370, mcp up 361, jamgate up 342, Google Workspace up 339
MCP News is a factual catalog of Model Context Protocol servers and clients plus a primary-sourced news feed for the MCP ecosystem. Every record carries source URLs, a verification date, and a calibrated confidence score, so claims like "first-party server" or "supports the 2026-07-28 stateless revision" can be checked rather than guessed at. Records that fall below the publishing threshold stay in moderation and never appear here.
We use one optional analytics cookie (Google Analytics) to understand readership. No ads, no cross-site tracking. Nothing is set unless you accept. See the privacy policy.
We use one analytics cookie (Google Analytics) to understand readership; in your region it is on by default and you can opt out any time. No ads, no cross-site tracking. See the privacy policy.