CVE-2026-64684 | Model Context Protocol RMCP SDK up to 2.0.x StreamableHttpClientTransport streamable_http_client.rs apply_custom_headers information disclosure

SecurityVulns

A vulnerability was found in Model Context Protocol RMCP SDK up to 2.0.x and classified as problematic. Affected by this issue is the function apply_custom_headers of the file crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs of the component StreamableHttpClientTransport. The manipulation results in information disclosure.

This vulnerability is reported as CVE-2026-64684. The attack can be launched remotely. No exploit exists.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More