VendorsApachedoris_mcp_serverall versions
Vulnerabilities

Apache Software Foundation Doris MCP (Model Context Protocol) Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2025-66336
Apache Doris MCP Server: SQL injection leading the authentication bypass
Published 2026-06-22 · Analyzed
8.1EPSS 0.006
CVE-2025-58337
Apache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode for doris-mcp-server MCP Server
Published 2025-11-05 · Analyzed
5.4EPSS 0.003
CVE-2025-66335
Apache Doris MCP Server: MCP SQL inject
Published 2026-04-20 · Analyzed
5.3EPSS 0.007