<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://mcp-news.com/news/kotlin-sdk-streamable-http-dos-cve-pair</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03</news:publication_date>
      <news:title>Kotlin SDK discloses two Streamable HTTP denial-of-service records, one unauthenticated, both fixed nine weeks earlier</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://mcp-news.com/news/mcp-inspector-2-5-0-oauth-revocation</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02</news:publication_date>
      <news:title>MCP Inspector 2.5.0 revokes OAuth tokens when you clear them, and stops retrying a subscription that was never acknowledged</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://mcp-news.com/news/ssh-mcp-classifier-bypass-critical-advisory</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-02</news:publication_date>
      <news:title>ssh-mcp discloses a critical bypass of the gate that enforces its read-only mode, and groups it with four earlier ones as the same defect</news:title>
    </news:news>
  </url>
</urlset>