mcp-server-fetch

Direct Vulnerabilities

Known vulnerabilities in the mcp-server-fetch package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Resource Exhaustion

<2026.8.18-r0
  • L
Origin Validation Error

<2026.8.18-r0
  • L
Authorization Bypass Through User-Controlled Key

<2026.8.18-r0
  • L
Resource Exhaustion

<2026.8.18-r0
  • L
Missing Authorization

<2026.8.18-r0
  • L
Improper Certificate Validation

<2026.7.4-r0
  • L
Resource Exhaustion

<2026.7.4-r0
  • C
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • L
Improper Input Validation

<2026.7.4-r0
  • L
Resource Exhaustion

<2026.7.4-r0
  • L
Interpretation Conflict

<2026.7.4-r0
  • L
Unintended Proxy or Intermediary ('Confused Deputy')

<2026.7.4-r0
  • L
Improper Validation of Specified Quantity in Input

<2026.7.4-r0
  • L
Improper Cleanup on Thrown Exception

<2026.7.4-r0
  • L
Improper Verification of Cryptographic Signature

<2026.7.4-r0
  • L
CVE-2025-7783

*
  • C
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • C
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • H
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • C
CVE-2026-4800

*
  • L
Improper Authentication

<2026.7.4-r0
  • H
Arbitrary Code Injection

*
  • L
Resource Exhaustion

*
  • L
GHSA-537c-gmf6-5ccf

<2026.7.4-r0
  • L
Resource Exhaustion

<2026.7.4-r0
  • L
CVE-2026-12143

*
  • L
CVE-2024-37890

*
  • L
Resource Exhaustion

<2026.6.16-r0
  • L
Allocation of Resources Without Limits or Throttling

<2026.6.16-r0
  • M
Improper Certificate Validation

<2026.6.16-r0
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

<2026.6.16-r0
  • L
XML External Entity (XXE) Injection

<2026.6.16-r0
  • M
Insecure Temporary File

<2026.6.16-r0
  • L
Use of Incorrectly-Resolved Name or Reference

<2026.6.16-r0
  • L
CVE-2026-48818

<2026.6.16-r0
  • L
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

<2026.6.16-r0
  • M
CVE-2026-26007

<2026.6.16-r0
  • M
Inefficient Regular Expression Complexity

<2026.6.16-r0
  • L
Link Following

<2026.6.16-r0
  • C
Out-of-Bounds

<2026.6.16-r0
  • L
Insufficient Verification of Data Authenticity

<2026.6.16-r0
  • L
Allocation of Resources Without Limits or Throttling

<2026.6.16-r0
  • M
HTTP Request Smuggling

<2026.6.16-r0
  • H
Directory Traversal

<2026.6.16-r0
  • M
Information Exposure

<2026.6.16-r0