CVE-2026-67431 | modelcontextprotocol ruby-sdk up to 0.22.x StreamableHTTPTransport improper authentication (EUVD-2026-50501)
A vulnerability classified as critical was found in modelcontextprotocol ruby-sdk up to 0.22.x. This impacts the function MCP::Server::Transports::StreamableHTTPTransport of the component StreamableHTTPTransport. Such manipulation leads to improper authentication.
This vulnerability is uniquely identified as CVE-2026-67431. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.