<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://mcp-news.com/news/rmcp-3-1-4-hardens-request-state-signing</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20</news:publication_date>
      <news:title>rmcp 3.1.4 requires 32-byte signing keys for MRTR request state and stops Debug from printing OAuth secrets</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://mcp-news.com/news/contentful-mcp-export-space-pat-redirect</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-19</news:publication_date>
      <news:title>Contentful MCP Server advisory: two migration tools let a model redirect the server&apos;s access token to any host</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://mcp-news.com/news/github-mcp-server-1-10-0-security-release</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-19</news:publication_date>
      <news:title>GitHub MCP Server 1.10.0 gates repository deletion behind elicitation and hardens credentials, symlinks and request limits</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://mcp-news.com/news/java-sdk-bounds-unbounded-http-reads</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-19</news:publication_date>
      <news:title>Official Java SDK caps HTTP reads in both directions after two resource-exhaustion advisories</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://mcp-news.com/news/marimo-notebook-mcp-entry-code-injection</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-19</news:publication_date>
      <news:title>CVE record published for a marimo flaw where a notebook&apos;s own MCP server entry ran as a subprocess on open</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://mcp-news.com/news/mcp-inspector-2-3-0-oauth-overrides</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-19</news:publication_date>
      <news:title>MCP Inspector 2.3.0 adds per-server OAuth overrides and clears eight dependency advisories</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://mcp-news.com/news/searxng-mcp-three-advisories</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-19</news:publication_date>
      <news:title>Three advisories published for the SearXNG MCP server, including basic-auth credentials leaking through MCP logs and JSON-RPC errors</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://mcp-news.com/news/splunk-mcp-server-app-deserialization-rce</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-19</news:publication_date>
      <news:title>Splunk discloses command execution in its MCP Server app through unchecked deserialization in credential management</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://mcp-news.com/news/apify-actors-mcp-token-leak-cve-reaches-nvd</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18</news:publication_date>
      <news:title>CVE record published for an Apify MCP server flaw that could redirect a client&apos;s bearer token to a third-party host</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://mcp-news.com/news/context7-custom-instructions-prompt-injection-cve</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18</news:publication_date>
      <news:title>CVE record published for the Context7 custom-rules prompt injection Upstash fixed in February</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://mcp-news.com/news/apache-skywalking-mcp-ssrf-graphql-injection-cve</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18</news:publication_date>
      <news:title>CVE record published for the Apache SkyWalking MCP SSRF and GraphQL injection fixed in April</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://mcp-news.com/news/codewhale-approval-requirement-bypass-cves</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18</news:publication_date>
      <news:title>Two CodeWhale CVEs record tools that declared themselves auto-approved and overrode the user&apos;s approval policy</news:title>
    </news:news>
  </url>
</urlset>