DReview status: Durable. S001
STANDARD2010-03-26Version 2.0Primary standard
JSON-RPC Working Group
Supports: Defines requests, responses, notifications, errors, and batching used by MCP. Requests, responses, notifications, errors and transport independence. Request, response, notification, error and transport-agnostic RPC semantics Request, response, notification and error object semantics used by MCP.
DReview status: Durable. S002
DOCUMENTATION2016-06-27
Microsoft
Supports: Primary architectural background for editor-client/language-server reuse and JSON-RPC capability negotiation.
DReview status: Durable. S003
RFC2012-10
IETF
Supports: Background for delegated authorization terminology.
DReview status: Durable. S004
RFC2015-09Version RFC 7636Formal standards source
IETF
Supports: PKCE requirements used in MCP authorization. PKCE security properties for public clients
DReview status: Durable. S005
RFC2020-09Version RFC 8707Formal standards source
IETF
Supports: Resource Indicators added to MCP authorization hardening. Audience-bound resource parameter
DReview status: Durable. S006
RFC2025-04Version RFC 9728Formal standards source
IETF
Supports: Protected-resource metadata used by MCP resource servers. Protected-resource metadata used by MCP authorization
LReview status: Live check required. S007
INTERNET-DRAFTLIVE
IETF OAuth WG
Supports: Status and evolving basis of MCP authorization framework.
DReview status: Durable. S008
STANDARD2014-11-08
OpenID Foundation
Supports: Discovery mechanism supported in MCP 2025-11-25.
DReview status: Durable. S009
BLOG2023-03-23
OpenAI
Supports: Pre-MCP vendor plugin architecture using manifests, APIs, and OAuth. Earlier vendor-specific plugin model using manifests, OpenAPI and OAuth.
DReview status: Durable. S010
BLOG2023-06-13Primary vendor
OpenAI
Supports: Pre-MCP model function-calling history. Pre-MCP function-calling history and structured model action selection. Public OpenAI function-calling introduction, JSON arguments and early security warning
LReview status: Live check required. S011
DOCUMENTATIONLIVEPrimary vendor
Anthropic
Supports: Distinguishes vendor tool-use APIs from MCP interoperability. Client versus server tools and structured tool_use behavior
DReview status: Durable. S012
GIT REPOSITORY2024-09-24
Model Context Protocol
Supports: Repository creation predates the public announcement.
DReview status: Durable. S013
GIT COMMIT2024-09-24Version early draft
Model Context Protocol
Supports: Earliest public commit; states LSP inspiration, host/client/server/session terminology, resources, prompts, tools, sampling, stdio and SSE. Earliest public repository evidence and explicit LSP inspiration.
DReview status: Durable. S014
GIT COMMIT2024-09-24
Model Context Protocol
Supports: Earliest public TypeScript SDK evidence.
DReview status: Durable. S015
GIT COMMIT2024-09-24
Model Context Protocol
Supports: Earliest public Python SDK evidence.
DReview status: Durable. S016
GIT COMMIT2024-10-03Version early draft
Model Context Protocol
Supports: Shows capability declarations still being refined before launch.
DReview status: Durable. S017
GIT COMMIT2024-10-16Version early draft
Model Context Protocol
Supports: Pre-launch documentation work.
DReview status: Durable. S018
GIT REPOSITORY2024-11-19
Model Context Protocol
Supports: Repository creation and evolution of reference servers.
DReview status: Durable. S019
GIT COMMIT2024-11-19
Model Context Protocol
Supports: First public reference-server monorepo commit. Earliest verified public reference server set.
DReview status: Durable. S020
GIT TREE2024-11-19
Model Context Protocol
Supports: Confirms initial public directories including everything, Google Drive, Git, Postgres, and Puppeteer.
DReview status: Durable. S021
BLOG2024-11-25Version LaunchPrimary vendor
Anthropic
Supports: Public launch, creators, SDKs, Claude Desktop support, example integrations, and stated integration problem. Public announcement, integration-fragmentation rationale, SDKs, Claude Desktop and example servers. MCP public announcement, integration-fragmentation rationale, initial SDK and host context Public launch, initial local-first integration rationale, initial SDK and host context
DReview status: Durable. S022
BLOG2024-11-25
Zed Industries
Supports: Launch-day non-Anthropic host integration and explicit LSP comparison. Zed launch-day MCP integration and collaboration with Anthropic.
LReview status: Live check required. S023
READMELIVE
Model Context Protocol
Supports: Current creator credit to David Soria Parra and Justin Spahr-Summers. Official creator credit for David Soria Parra and Justin Spahr-Summers.
DReview status: Durable. S024
SPEC2024-11-05Version 2024-11-05Authoritative specification
Model Context Protocol
Supports: Authoritative launch-era specification overview. Launch-era stateful architecture, initialization, stdio, HTTP+SSE and original capabilities. Initial released protocol overview and date-based revision Launch-era architecture, lifecycle, capabilities and trust guidance
DReview status: Durable. S025
SPEC2024-11-05Version 2024-11-05Authoritative specification
Model Context Protocol
Supports: Launch-era host/client/server architecture. Launch-era host, client, server, JSON-RPC and stateful-session architecture
DReview status: Durable. S026
SPEC2024-11-05Version 2024-11-05
Model Context Protocol
Supports: Initialize/initialized handshake, version and capability negotiation. Launch-era initialize/initialized lifecycle and capability negotiation.
DReview status: Durable. S027
SPEC2024-11-05Version 2024-11-05Authoritative specification
Model Context Protocol
Supports: stdio and HTTP+SSE semantics. Original stdio and HTTP+SSE transport behavior Original stdio and HTTP+SSE transport semantics
DReview status: Durable. S028
SPEC2024-11-05Version 2024-11-05Authoritative specification
Model Context Protocol
Supports: Launch-era tool listing and invocation. Launch-era tool definition and model-controlled interaction guidance Launch-era tool discovery, invocation and human-control guidance
DReview status: Durable. S029
SPEC2024-11-05Version 2024-11-05Authoritative specification
Model Context Protocol
Supports: URI-addressed resources, templates, and subscriptions. Launch-era resource semantics Launch-era resources, subscriptions and data exposure semantics
DReview status: Durable. S030
SPEC2024-11-05Version 2024-11-05Authoritative specification
Model Context Protocol
Supports: Server-exposed prompt templates and user-controlled workflows. Launch-era prompt-template semantics
DReview status: Durable. S031
SPEC2024-11-05Version 2024-11-05
Model Context Protocol
Supports: Client-declared filesystem/project boundaries.
DReview status: Durable. S032
SPEC2024-11-05Version 2024-11-05Authoritative specification
Model Context Protocol
Supports: Server requests model sampling through client/host. Launch-era server-to-client sampling and user-control expectations
DReview status: Durable. S033
SPEC2024-11-05Version 2024-11-05
Model Context Protocol
Supports: Protocol logging method and notifications.
DReview status: Durable. S034
SPEC2024-11-05Version 2024-11-05
Model Context Protocol
Supports: Argument-completion utility present at launch.
DReview status: Durable. S035
SPEC2025-03-26Version 2025-03-26
Model Context Protocol
Supports: Authoritative March 2025 revision.
DReview status: Durable. S036
CHANGELOG2025-03-26Version 2025-03-26Authoritative specification
Model Context Protocol
Supports: OAuth framework, Streamable HTTP, batching, tool annotations, audio, progress, completions capability. OAuth-based authorization, Streamable HTTP, JSON-RPC batching, tool annotations, audio, progress text and completions capability entered the released specification. OAuth framework, Streamable HTTP, batching, annotations, audio and completions Initial authorization framework, Streamable HTTP, annotations and batching Streamable HTTP, OAuth framework, batching and tool annotations.
DReview status: Durable. S037
SPEC2025-03-26Version 2025-03-26Authoritative specification
Model Context Protocol
Supports: First protocol authorization framework. Initial OAuth-oriented remote authorization framework First protocol authorization framework for HTTP deployments
DReview status: Durable. S038
SPEC2025-03-26Version 2025-03-26
Model Context Protocol
Supports: Original Streamable HTTP, stateful session, optional SSE, backwards compatibility. Original Streamable HTTP semantics, including POST/GET, optional SSE, resumability and optional Mcp-Session-Id session management.
DReview status: Durable. S039
PR2025-03-26Version 2025-03-26
Model Context Protocol
Supports: Design history for replacing HTTP+SSE.
DReview status: Durable. S040
PR2025-03-26Version 2025-03-26
Model Context Protocol
Supports: Authorization proposal and merge history.
DReview status: Durable. S041
PR2025-03-26Version 2025-03-26
Model Context Protocol
Supports: Origin of read-only, destructive, idempotent, and open-world hints.
DReview status: Durable. S042
SPEC2025-06-18Version 2025-06-18
Model Context Protocol
Supports: Authoritative June 2025 revision.
DReview status: Durable. S043
CHANGELOG2025-06-18Version 2025-06-18Authoritative specification
Model Context Protocol
Supports: Batching removal, structured output, resource-server classification, Resource Indicators, elicitation, resource links. JSON-RPC batching was removed; structured tool output, resource links, elicitation and authorization hardening were added. Batching removal, structured output, elicitation and authorization hardening Resource-server classification, protected-resource metadata, Resource Indicators and structured output Removal of batching, structured tool output, elicitation and authorization hardening.
DReview status: Durable. S044
SPEC2025-06-18Version 2025-06-18Authoritative specification
Model Context Protocol
Supports: OAuth resource-server model, protected resource metadata, PKCE, Resource Indicators. Resource Indicators, token audience validation and resource-server model Audience restrictions, protected resource metadata and token validation
DReview status: Durable. S045
SPEC2025-06-18Version 2025-06-18Authoritative specification
Model Context Protocol
Supports: Structured tool output and output schema. Structured tool output and outputSchema semantics
DReview status: Durable. S046
SPEC2025-06-18Version 2025-06-18
Model Context Protocol
Supports: Server-initiated user information request capability.
DReview status: Durable. S047
SPEC2025-06-18Version 2025-06-18
Model Context Protocol
Supports: Token passthrough, confused deputy, least privilege, and proxy risks.
DReview status: Durable. S048
SPEC2025-11-25Version 2025-11-25
Model Context Protocol
Supports: Authoritative one-year revision.
DReview status: Durable. S049
CHANGELOG2025-11-25Version 2025-11-25Authoritative specification
Model Context Protocol
Supports: OIDC discovery, icons, incremental scopes, URL elicitation, sampling tools, client metadata documents, experimental tasks, governance. OIDC discovery, icon metadata, incremental scope consent, richer elicitation, CIMD, tool use in sampling and experimental Tasks entered the released specification. One-year revision changes including experimental Tasks OIDC discovery, CIMD, incremental consent, URL elicitation and experimental Tasks OIDC discovery, CIMD, expanded elicitation, experimental Tasks and governance changes.
DReview status: Durable. S050
SPEC2025-11-25Version 2025-11-25
Model Context Protocol
Supports: Experimental core Tasks semantics.
DReview status: Durable. S051
SPEC2025-11-25Version 2025-11-25
Model Context Protocol
Supports: Sensitive/out-of-band user interactions.
DReview status: Durable. S052
BLOG2025-09-26Version 2025-11-25
Model Context Protocol
Supports: RC date and 14-day validation process.
DReview status: Durable. S053
RELEASE CANDIDATE2026-05-21Version 2026-07-28-rcOfficial project
Model Context Protocol
Supports: RC chronology and rationale for stateless core, extensions, tasks, apps, and deprecation. RC date, validation window, motivations and distinction between RC and GA. RC chronology and technical motivation for stateless architecture Infrastructure motivation for statelessness, routing and caching Release-candidate chronology and before/after architecture rationale.
LReview status: Live check required. S054
SPEC2026-07-28Version 2026-07-28
Model Context Protocol
Supports: Current authoritative specification at verification date. Current authoritative protocol overview, roles, JSON-RPC basis, primitives, security principles.
DReview status: Durable. S055
CHANGELOG2026-07-28Version 2026-07-28Authoritative specification
Model Context Protocol
Supports: Stateless core, discovery, MRTR, subscriptions/listen, routing headers, caching, tasks extension, deprecations. Removal of handshake and sessions; discovery, subscriptions, routing, caching, extensions and deprecations. Canonical list of 2026 additions, removals, deprecations and compatibility effects Stateless core, removal of sessions and initialization, routing headers, cache scope, auth hardening, MRTR and deprecations Removal of initialize, initialized, protocol sessions and Mcp-Session-Id; addition of server/discover, MRTR, routing headers and cacheable results.
DReview status: Durable. S056
SPEC2026-07-28Version 2026-07-28Authoritative specification
Model Context Protocol
Supports: Modern/legacy/dual-era compatibility and per-request versioning. Current version declaration and compatibility behavior Per-request version declaration, modern versus legacy eras, discovery and dual-era compatibility.
DReview status: Durable. S057
SPEC2026-07-28Version 2026-07-28Authoritative specification
Model Context Protocol
Supports: Current transport bindings and no server-initiated JSON-RPC requests in modern core. Current stdio and Streamable HTTP semantics Current sessionless HTTP transport and request header rules Transport is separate from protocol semantics; current stdio and Streamable HTTP transports.
PReview status: Periodic review. S058
BLOG2026-07-28Version 2026-07-28Official project
Model Context Protocol
Supports: GA announcement, SDK support, architecture rationale, download claims. GA announcement and maintainer explanation of the stateless revision. GA release, stateless core, MRTR, routing, caching, auth and extensions Maintainer explanation of the current release GA announcement and maintainers’ explanation of stateless architecture, discovery, MRTR, caching and extensions.
DReview status: Durable. S059
EXTENSION2026-01-26Version io.modelcontextprotocol/uiOfficial project
Model Context Protocol
Supports: First official extension; sandboxed server-provided UI. Launch of the first official MCP extension and historical context. MCP Apps origin and server-provided UI concept
DReview status: Durable. S060
SEP2026-07-28Version io.modelcontextprotocol/tasks
Model Context Protocol
Supports: Tasks moved from experimental core to official extension. Migration of Tasks from experimental core into an official extension.
DReview status: Durable. S061
SEP2026-07-28Version 2026-07-28
Model Context Protocol
Supports: Removal of handshake/sessions and per-request metadata model. Motivation and proposal history for removing initialization state.
DReview status: Durable. S062
SEP2026-07-28Version 2026-07-28
Model Context Protocol
Supports: InputRequiredResult retry pattern.
PReview status: Periodic review. S063
EXTENSION2026-06-18Version EMA
Model Context Protocol
Supports: Stable enterprise authorization extension.
LReview status: Live check required. S064
ROADMAP2026-08-22Version Post-2026-07-28Official project blog
Model Context Protocol
Supports: Post-2026-07-28 priorities; proposals, not shipped features. Current roadmap priorities; proposals are not shipped features. Agent identity, enterprise-ready security and HTTP hardening priorities Current roadmap and retrospective confirmation of session and handshake removal.
LReview status: Live check required. S065
POLICY2026-07-28
Model Context Protocol
Supports: Active, Deprecated, Removed states and minimum deprecation window.
DReview status: Durable. S066
REGISTRY2025-09-08Version Registry previewOfficial project blog
Model Context Protocol
Supports: Official registry preview launch and origin history. Registry launch date, preview status and collaborative origin. Registry launch, namespace verification and metadata role
LReview status: Live check required. S067
REGISTRYLIVEVersion CurrentOfficial docs
Model Context Protocol
Supports: Current preview status, metadata role, namespaces, package-registry relationship, scanning limits. Official registry scope, metadata role, namespace verification and security-scanning limits. Registry metadata role and limits; code/package scanning delegated elsewhere
LReview status: Live check required. S068
REGISTRYLIVE
Model Context Protocol
Supports: Current registry endpoint.
DReview status: Durable. S069
GOVERNANCE2025-07-31
Model Context Protocol
Supports: SEP process and maintainer roles. Formal governance roles and SEP process.
DReview status: Durable. S070
GOVERNANCE2025-12-09
Model Context Protocol
Supports: Donation to AAIF, technical autonomy, project-reported adoption statistics. MCP's Linux Foundation/AAIF organizational home and retained technical governance.
LReview status: Live check required. S071
GOVERNANCELIVE
Model Context Protocol
Supports: Current lead/core maintainer structure and LF project status. Current maintainer structure and individual rather than corporate membership.
LReview status: Live check required. S072
LICENSELIVE
Model Context Protocol
Supports: MIT-to-Apache-2.0 transition and CC BY 4.0 documentation license.
LReview status: Live check required. S073
GOVERNANCE2026-02-23
Model Context Protocol
Supports: Tier 1–3 requirements and conformance-based governance. Meaning of SDK tiers and maintenance/conformance expectations.
DReview status: Durable. S074
SEP2026-01-15
Model Context Protocol
Supports: Contributor progression and governance transparency.
LReview status: Live check required. S075
SDK2024-11-25
Model Context Protocol
Supports: Official launch SDK; current status live-check.
LReview status: Live check required. S076
SDK2024-11-25
Model Context Protocol
Supports: Official launch SDK; current status live-check.
LReview status: Live check required. S077
SDKLIVE
Model Context Protocol
Supports: Official SDK status and history.
LReview status: Live check required. S078
SDKLIVE
Model Context Protocol
Supports: Official SDK status and history.
LReview status: Live check required. S079
SDKLIVE
Model Context Protocol
Supports: Official SDK status and history.
LReview status: Live check required. S080
SDKLIVE
Model Context Protocol
Supports: Official SDK status and history.
LReview status: Live check required. S081
SDKLIVE
Model Context Protocol
Supports: Official SDK status and history.
LReview status: Live check required. S082
SDKLIVE
Model Context Protocol
Supports: Official SDK status and history.
LReview status: Live check required. S083
SDKLIVE
Model Context Protocol
Supports: Official SDK status and history.
DReview status: Durable. S084
SDK RELEASE2026-07-27
Model Context Protocol
Supports: Ruby 1.0 and Tier 2 milestone.
DReview status: Durable. S085
SDK RELEASE2025-09-05
Model Context Protocol
Supports: PHP official GA announcement and initial server-only scope.
LReview status: Live check required. S086
SDKLIVE
Model Context Protocol
Supports: Current official PHP SDK status.
DReview status: Durable. S087
VENDOR ADOPTION2025-04-07
Microsoft / Visual Studio Code
Supports: Official VS Code MCP host/client support and LSP influence statement. Initial official VS Code MCP host support.
DReview status: Durable. S088
VENDOR ADOPTION2025-05-14
Microsoft / Visual Studio Code
Supports: Expansion from tools toward richer capabilities and installation UX. VS Code host behavior, tool picker and server integration.
Evidence note: First-party product documentation rechecked and normalized on 2026-08-25; the package URL remains in the package source map.
DReview status: Durable. S089
VENDOR ADOPTION2025-05-21Primary vendor
OpenAI
Supports: First unequivocal official remote MCP support in OpenAI API product. Official remote MCP support in the Responses API. First official OpenAI remote MCP support announcement
LReview status: Live check required. S090
VENDOR DOCUMENTATIONLIVEOfficial SDK
OpenAI
Supports: Current hosted, Streamable HTTP, SSE, and stdio MCP integration modes. MCP schema conversion, name prefixing, hosted/local transport, filtering, approvals and caching Hosted, Streamable HTTP, legacy SSE and stdio MCP client options; manager for multiple servers.
DReview status: Durable. S091
VENDOR ADOPTION2025-04-01
Amazon Web Services
Supports: Official open-source AWS server suite. Official AWS server suite adoption.
DReview status: Durable. S092
VENDOR ADOPTION2025-04-22
Google Cloud
Supports: Official Google Cloud server/platform support. Official Google Cloud MCP server/platform adoption.
DReview status: Durable. S093
VENDOR ADOPTION2025-03-25
Cloudflare
Supports: Remote hosting, OAuth provider, and Agents SDK support. Early official remote MCP hosting and OAuth infrastructure.
DReview status: Durable. S094
VENDOR ADOPTION2025-04-30
Cloudflare
Supports: Rapid transport adoption and dual-transport migration.
DReview status: Durable. S095
VENDOR ADOPTION2025-05-01
Cloudflare
Supports: Official managed remote servers.
PReview status: Periodic review. S096
VENDOR ADOPTION2025-05-01
Cloudflare and vendors
Supports: Remote servers from multiple SaaS vendors; useful but partly promotional.
DReview status: Durable. S097
VENDOR ADOPTION2025-05-01
Atlassian
Supports: Official Atlassian remote-server beta.
LReview status: Live check required. S098
VENDOR DOCUMENTATIONLIVE
GitHub
Supports: Official GitHub server implementation.
DReview status: Durable. S099
VENDOR ADOPTION2025-09-04
GitHub
Supports: Official remote server GA and authorization model.
LReview status: Live check required. S100
VENDOR DOCUMENTATIONLIVE
Cursor
Supports: Current host support; first historical date remains separately qualified.
DReview status: Durable. S101
VENDOR ADOPTION2025-04-15
Cursor
Supports: Early dated Cursor MCP capability evidence.
DReview status: Durable. S102
VENDOR ADOPTION2025-05
JetBrains
Supports: Official JetBrains host/client support.
LReview status: Live check required. S103
VENDOR DOCUMENTATIONLIVE
Notion
Supports: Official Notion server documentation; current state live-check.
LReview status: Live check required. S104
FRAMEWORKLIVE
LangChain
Supports: Framework adapter demonstrating MCP-to-native-tool mapping.
LReview status: Live check required. S105
FRAMEWORKLIVE
LlamaIndex
Supports: Framework integration.
LReview status: Live check required. S106
FRAMEWORKLIVE
Microsoft
Supports: MCP adaptation into Semantic Kernel plugin abstraction.
LReview status: Live check required. S107
FRAMEWORKLIVE
Microsoft
Supports: MCP integration in AutoGen.
DReview status: Durable. S108
SECURITY2025-04-01Version Session-era clientsOriginal research
Invariant Labs
Supports: Canonical disclosure of hidden tool-description attacks, rug pulls, and tool shadowing. Original tool-poisoning, rug-pull and cross-server-shadowing research. Original public disclosure of tool poisoning, shadowing and rug-pull patterns
DReview status: Durable. S109
SECURITY ADVISORY2025-06-13Version <0.14.1Vendor advisory / CVE
Model Context Protocol
Supports: Inspector proxy exposure; implementation vulnerability, not core-protocol semantics. Representative host/developer-tool implementation vulnerability. Remote code execution due to unauthenticated Inspector proxy; patched/fixed status: 0.14.1
Evidence note: Layer: Host/developer tool. Verify current affected and fixed ranges before publication.
DReview status: Durable. S110
SECURITY ADVISORY2025-09-06Version <0.16.6Vendor advisory / CVE
Model Context Protocol
Supports: Inspector implementation vulnerability with potential command-execution path. Representative Inspector UI vulnerability and patch boundary. Cross-site scripting in Inspector; patched/fixed status: 0.16.6
Evidence note: Layer: Host/developer tool. Verify current affected and fixed ranges before publication.
DReview status: Durable. S111
SECURITY ADVISORY2025-12-02Version <1.24.0Vendor advisory / CVE
Model Context Protocol
Supports: HTTP SDK default-binding risk; stdio unaffected. Representative local HTTP SDK exposure and Origin/bind protection. DNS rebinding protection disabled by default for unauthenticated localhost HTTP servers; patched/fixed status: 1.24.0
Evidence note: Layer: SDK/transport. Verify current affected and fixed ranges before publication.
DReview status: Durable. S112
SECURITY ADVISORY2025-12-02Version <1.23.0Vendor advisory / CVE
Model Context Protocol
Supports: Python HTTP SDK default-binding risk. Representative Python SDK DNS-rebinding vulnerability. DNS rebinding protection disabled by default for localhost HTTP servers; patched/fixed status: 1.23.0
Evidence note: Layer: SDK/transport. Verify current affected and fixed ranges before publication.
DReview status: Durable. S113
SECURITY ADVISORY2025-07-04
Model Context Protocol
Supports: SDK validation resource-exhaustion issue.
DReview status: Durable. S114
SECURITY ADVISORY2026-01-07
Model Context Protocol
Supports: SDK parsing/regular-expression vulnerability.
DReview status: Durable. S115
SECURITY ADVISORY2026-04-07
Model Context Protocol
Supports: Java SDK HTTP exposure hardening.
PReview status: Periodic review. S116
RESEARCH2025
Academic researchers
Supports: Academic evaluation of malicious MCP tool metadata and behavior.
PReview status: Periodic review. S117
RESEARCH2025
Academic researchers
Supports: Broader empirical MCP security analysis.
DReview status: Durable. S118
PROTOCOL2025-04-09
Google
Supports: Agent-to-agent protocol launch and complementary positioning to MCP.
DReview status: Durable. S119
GOVERNANCE2025-06-23
Linux Foundation
Supports: A2A governance transition.
DReview status: Durable. S120
PROTOCOL2025-03-17
IBM
Supports: ACP as an agent-to-agent protocol, not an MCP substitute at the same layer.
DReview status: Durable. S121
SPEC2026-07-28Version 2026-07-28
Model Context Protocol
Supports: Current host, client, server definitions; one client per server; stateless per-request model. Current host, client, and server definitions; one host manages multiple clients; each client relates to one server; stateless per-request architecture.
DReview status: Durable. S122
DOCUMENTATION2026-07-28Version 2026-07-28
Model Context Protocol
Supports: Conceptual architecture, data and transport layers, local and remote servers.
DReview status: Durable. S123
SPEC2026-07-28Version 2026-07-28Authoritative specification
Model Context Protocol
Supports: Tool discovery, schemas, invocation, result content, structured output, annotations and security rules. Current tool schemas, calls, results, annotations and state-handle guidance Current tool semantics, annotations, schemas, explicit handles and security considerations Tool discovery and invocation, host human-in-the-loop guidance, annotations, explicit handles and MRTR.
DReview status: Durable. S124
SPEC2026-07-28Version 2026-07-28Authoritative specification
Model Context Protocol
Supports: URI-identified resources, list/read/templates and subscriptions behavior. Current resource primitive Server-exposed resources, URI identification, list/read behavior and subscriptions.
DReview status: Durable. S125
SPEC2026-07-28Version 2026-07-28Authoritative specification
Model Context Protocol
Supports: Protocol-exposed prompt templates, arguments, list/get behavior and user control. Current prompt primitive Server-exposed prompt templates and host presentation.
DReview status: Durable. S126
SPEC2026-07-28Version 2026-07-28
Model Context Protocol
Supports: Server requests for user input, form and URL modes, restrictions on sensitive data. Current client-side elicitation through MRTR and host-controlled user interaction.
DReview status: Durable. S127
SPEC2026-07-28Version 2026-07-28Authoritative specification
Model Context Protocol
Supports: Mandatory server/discover implementation and optional client invocation for versions and capabilities. Optional sessionless capability and version discovery server/discover semantics, supported versions and capabilities, optional client use, self-reported identity caveat.
DReview status: Durable. S128
SPEC2026-07-28Version 2026-07-28
Model Context Protocol
Supports: Cache hints and scope for complete list/read/discovery results.
DReview status: Durable. S129
SPEC2026-07-28Version 2026-07-28
Model Context Protocol
Supports: Current mechanism for additional client input without server-initiated JSON-RPC requests.
DReview status: Durable. S130
SPEC2026-07-28Version 2026-07-28Authoritative specification
Model Context Protocol
Supports: JSON-RPC messages, current statelessness, explicit state identifiers and authorization applicability. Current JSON-RPC base messages and request metadata JSON-RPC basis, current message directions, requests, responses, notifications and result types.
DReview status: Durable. S131
SPEC2026-07-28Version 2026-07-28
Model Context Protocol
Supports: Current remote transport, one POST endpoint, optional request-scoped SSE, routing headers and security. Current single-endpoint HTTP behavior, removal of GET stream and protocol sessions, request-scoped SSE, Origin requirements.
DReview status: Durable. S132
SPEC2026-07-28Version 2026-07-28
Model Context Protocol
Supports: Local subprocess transport, newline-delimited JSON-RPC and stdout/stderr requirements. Local subprocess lifecycle, stdin/stdout framing, stderr logging, shutdown and restart behavior.
DReview status: Durable. S133
SPEC2026-07-28Version 2026-07-28Authoritative specification
Model Context Protocol
Supports: Current HTTP authorization framework, OAuth resource-server roles, protected resource metadata and resource indicators. Current HTTP authorization roles, metadata, issuer validation, Resource Indicators, token handling and CIMD preference
PReview status: Periodic review. S134
SECURITY GUIDANCELIVE; verified 2026-08-25Version 2026-07-28Official project
Model Context Protocol
Supports: Confused deputy, token passthrough, SSRF, state handles, stdio proxy, redirect and issuer security. Layered security guidance, token handling and deployment risks Current official guidance on confused deputy, token passthrough, SSRF, local servers, state handles and OAuth URLs
DReview status: Durable. S135
SPEC2026-07-28Version 2026-07-28
Model Context Protocol
Supports: Roots, sampling, logging, DCR and HTTP+SSE deprecation status and migration paths.
PReview status: Periodic review. S136
EXTENSIONLIVE; verified 2026-08-25Version io.modelcontextprotocol/uiAuthoritative extension docs
Model Context Protocol
Supports: Interactive HTML interfaces, tool-linked UI resources, sandbox and host support variability. Server-provided interactive UI, sandboxing and host security boundary
PReview status: Periodic review. S137
EXTENSIONLIVE; verified 2026-08-25Version io.modelcontextprotocol/tasksAuthoritative extension docs
Model Context Protocol
Supports: Durable asynchronous operations, task IDs, polling, input and cancellation semantics. Long-running task handles and lifecycle semantics
LReview status: Live check required. S138
SDK INDEXLIVE; verified 2026-08-25Version Current
Model Context Protocol
Supports: Current official SDK list and tier assignments.
PReview status: Periodic review. S139
DOCUMENTATIONLIVEVersion Current
Microsoft
Supports: LSP client/server architecture and the M × N integration problem.
LReview status: Live check required. S140
VENDOR DOCUMENTATIONLIVE; verified 2026-08-25Version Current
OpenAI
Supports: Current ChatGPT remote MCP limitations, local-server tunnel requirement and plan-dependent access. ChatGPT as a host with remote MCP connector support and MCP Apps; current availability and remote-only direct connection constraints.
Evidence note: First-party product documentation rechecked and normalized on 2026-08-25; the package URL remains in the package source map.
LReview status: Live check required. S141
VENDOR DOCUMENTATIONLIVE; verified 2026-08-25Version Current
Microsoft / Visual Studio Code
Supports: Current local/remote installation, trust, sandboxing, prompts/resources/apps and enterprise policy support. VS Code host/client support for tools, resources, prompts and MCP Apps; local and remote servers, trust and policy.
Evidence note: First-party product documentation rechecked and normalized on 2026-08-25; the package URL remains in the package source map.
DReview status: Durable. S142
VENDOR ADOPTION2025-06-12Version 2025-era
Microsoft / Visual Studio Code
Supports: Official authorization, prompts, resources and sampling adoption.
DReview status: Durable. S143
VENDOR ADOPTION2026-01-26Version MCP Apps
Microsoft / Visual Studio Code
Supports: Official MCP Apps host support.
LReview status: Live check required. S144
VENDOR DOCUMENTATION2026-06-18Version Current
Google
Supports: Gemini CLI support for stdio, legacy SSE and Streamable HTTP, tools/resources/prompts, OAuth and confirmations. Gemini CLI local and remote MCP support and host permission flow.
Evidence note: First-party product documentation rechecked and normalized on 2026-08-25; the package URL remains in the package source map.
LReview status: Live check required. S145
VENDOR DOCUMENTATIONLIVE; verified 2026-08-25Version Current
Anthropic
Supports: Claude custom remote MCP connector availability and trust cautions. Claude remote connector behavior and cloud-originated connections.
LReview status: Live check required. S146
VENDOR DOCUMENTATIONLIVE; verified 2026-08-25Version Current
Anthropic
Supports: Remote connectors connect from Anthropic cloud and product terminology differs from protocol roles.
DReview status: Durable. S147
SECURITY ADVISORY2026Version TypeScript SDK 1.10.0–1.25.3Vendor advisory / CVE
GitHub Advisory Database
Supports: Representative multi-client isolation implementation defect. Cross-client response data leakage when server/transport instances are reused; patched/fixed status: 1.26.0
Evidence note: Layer: SDK/multi-tenancy. Verify current affected and fixed ranges before publication.
PReview status: Periodic review. S148
SEO GUIDANCE2025-12-10Version CurrentPrimary search-engine guidance
Google Search Central
Supports: People-first, original, well-sourced content and no preferred word count. People-first, original, trustworthy content and authorship guidance People-first content, no preferred word count, authorship/process transparency and satisfying user intent.
PReview status: Periodic review. S149
SEO GUIDANCE2025-12-10Version Current
Google Search Central
Supports: Accuracy, quality, relevance and transparent production context.
PReview status: Periodic review. S150
SEO GUIDANCE2025-12-10Version Current
Google Search Central
Supports: Descriptive, concise and consistent title/H1 recommendations. Descriptive concise titles, distinctive H1 and avoidance of keyword stuffing.
PReview status: Periodic review. S151
SEO GUIDANCE2025-12-10Version Current
Google Search Central
Supports: Structured data implementation and validation guidance.
PReview status: Periodic review. S152
SEO GUIDANCE2025-12-10Version CurrentPrimary search-engine guidance
Google Search Central
Supports: Article author, date, headline and image markup guidance. Article structured-data recommendations
PReview status: Periodic review. S153
SEO GUIDANCE2025-12-10Version CurrentPrimary search-engine guidance
Google Search Central
Supports: BreadcrumbList implementation and validation. BreadcrumbList markup guidance BreadcrumbList implementation and validation guidance.
PReview status: Periodic review. S154
SEO GUIDANCE2023-08-08Version Current policy context
Google Search Central
Supports: FAQ rich results are generally restricted to authoritative government and health sites.
PReview status: Periodic review. S155
SEO GUIDANCE2026-07Version CurrentPrimary search-engine guidance
Google Search Central
Supports: JSON-LD recommendation, relevance, accuracy and no guarantee of rich-result display. Accurate visible structured data and no rich-result guarantee
DReview status: Durable. S156
SPEC2025-03-26Version 2025-03-26Authoritative specification
Model Context Protocol
Supports: Initialization, protocol-version agreement, capability negotiation, initialized notification and session-era lifecycle semantics. Initialization, version and capability negotiation in March 2025 Stateful initialization and negotiated capabilities during the first Streamable HTTP era.
LReview status: Live check required. S157
Protocol specification2026-03-12Version 1.0.0; latest released specification rechecked 2026-08-25
A2A Project
Supports: The A2A 1.0 specification defines agent discovery, messages, tasks, artifacts, versioning, security, and multiple protocol bindings.
DReview status: Durable. S158
SPEC2025-03-26Version 2025-03-26Authoritative specification
Model Context Protocol
Supports: Tool annotations and March 2025 tool semantics Tool annotations as descriptive hints rather than guarantees
DReview status: Durable. S159
SPEC2025-06-18Version 2025-06-18Authoritative specification
Model Context Protocol
Supports: June 2025 retained initialization and sessions
DReview status: Durable. S160
SPEC2025-11-25Version 2025-11-25Authoritative specification
Model Context Protocol
Supports: Last released initialization/session lifecycle before 2026 stateless core Last released handshake/session-era lifecycle before the 2026 revision.
DReview status: Durable. S161
SPEC2025-11-25Version 2025-11-25Authoritative specification
Model Context Protocol
Supports: November 2025 tool fields and taskSupport execution metadata
DReview status: Durable. S162
BLOG2025-11-25Version 2025-11-25Official project
Model Context Protocol
Supports: Official retrospective and Tasks explanation
PReview status: Periodic review. S163
BLOG2026-03-16Version Current interpretationOfficial project
Model Context Protocol
Supports: Annotations are untrusted hints, not enforcement or prompt-injection defenses
LReview status: Live check required. S164
DOCS2026-08-25 (retrieved)Version CurrentOfficial project
Model Context Protocol
Supports: Extensions are separate from core protocol and version independently
LReview status: Live check required. S165
EXTENSION2026-08-25 (retrieved)Version Current extensionOfficial project
Model Context Protocol
Supports: Tasks are a separately versioned extension in the 2026 architecture
LReview status: Live check required. S166
SDK DOCS2026-08-25 (retrieved)Version SDK v2Official SDK
Model Context Protocol Python SDK
Supports: Modern versus handshake-era compatibility model
LReview status: Live check required. S167
SDK DOCS2026-08-25 (retrieved)Version SDK v2Official SDK
Model Context Protocol Python SDK
Supports: Local, remote and in-process client options Client connection forms: in-process, Streamable HTTP and stdio; client represents one server relationship.
LReview status: Live check required. S168
SDK DOCS2026-08-25 (retrieved)Version SDK v2Official SDK
Model Context Protocol TypeScript SDK
Supports: Per-era codecs and current auth migration details SDK implementation notes for discovery, identity and MRTR.
LReview status: Live check required. S169
DOCS2026-08-25 (retrieved)Version CurrentPrimary vendor
OpenAI
Supports: Current function definitions, tool loop, strict mode, tool choice and tool search
LReview status: Live check required. S170
DOCS2026-08-25 (retrieved)Version CurrentPrimary vendor
OpenAI
Supports: Remote MCP listing/calling, approvals and provider-hosted execution
LReview status: Live check required. S171
SDK DOCS2026-08-25 (retrieved)Version CurrentOfficial SDK
OpenAI
Supports: Function tools, hosted MCP tools, tool search, namespaces and execution options
LReview status: Live check required. S172
DOCS2026-08-25 (retrieved)Version CurrentPrimary vendor
OpenAI
Supports: Distinction between constrained model output and external tool result structure
LReview status: Live check required. S173
DOCS2026-08-25 (retrieved)Version CurrentPrimary vendor
Anthropic
Supports: Application tool execution and result-return loop
LReview status: Live check required. S174
DOCS2026-08-25 (retrieved)Version CurrentPrimary vendor
Anthropic
Supports: Deferred tool loading and large-catalog search
LReview status: Live check required. S175
DOCS2026-08-25 (retrieved)Version CurrentPrimary vendor
Anthropic
Supports: Messages API connection to remote MCP servers The beta Messages API connector uses tools from public HTTPS remote MCP servers over Streamable HTTP or legacy SSE.
Evidence note: First-party product documentation rechecked and normalized on 2026-08-25; the package URL remains in the package source map.
PReview status: Periodic review. S176
ENGINEERING2025-11-24Version Current-era analysisPrimary vendor
Anthropic
Supports: Tool search and large-catalog context/selection concerns
LReview status: Live check required. S177
DOCS2026-07-30 (page update)Version CurrentPrimary vendor
Google
Supports: Gemini function declarations, developer execution, parallel/compositional calls and remote MCP
LReview status: Live check required. S178
DOCS2026-08-25 (retrieved)Version CurrentPrimary vendor
Google
Supports: Provider-specific continuity requirements around tool calls
PReview status: Periodic review. S179
STANDARD2026-08-25 (retrieved)Version CurrentPrimary standard organization
OpenAPI Initiative
Supports: OpenAPI as a machine-readable HTTP API description
LReview status: Live check required. S180
STANDARD2026-08-25 (retrieved)Version Current indexPrimary standard organization
OpenAPI Initiative
Supports: Current OpenAPI versioned specifications
DReview status: Durable. S181
STANDARD2020-12Version 2020-12Primary standard
JSON Schema
Supports: Schema dialect used as current MCP default
LReview status: Live check required. S182
SERP COMPETITOR2026-03 (published)Version Competitor snapshotSecondary discovery only
MCP Institute
Supports: Current SERP framing and comparison gaps
LReview status: Live check required. S183
SERP COMPETITOR2026-04 (published)Version Competitor snapshotSecondary discovery only
Goodcall
Supports: Outdated HTTP+SSE framing in current results
LReview status: Live check required. S184
SERP COMPETITOR2025 (published)Version Competitor snapshotSecondary discovery only
AI Agents Kit
Supports: Stateful-MCP comparison still appearing in results
LReview status: Live check required. S185
SERP COMPETITOR2026 (retrieved)Version Competitor snapshotSecondary discovery only
Tetrate
Supports: Persistent-session framing and search-intent coverage
LReview status: Live check required. S186
SERP COMPETITOR2026 (published)Version Competitor snapshotSecondary discovery only
ClearPeaks
Supports: Example benchmark methodology and limits
DReview status: Durable. S187
SPEC2025-11-25Version 2025-11-25Authoritative specification
Model Context Protocol
Supports: Late-2025 authorization semantics and registration options
PReview status: Periodic review. S188
GOV GUIDANCE2026-05-20Version Predates 2026-07-28 GAGovernment primary source
NSA Artificial Intelligence Security Center
Supports: Government threat model and production recommendations; session-specific passages require version qualification
DReview status: Durable. S189
PRESS RELEASE2026-05-20Version Predates 2026-07-28 GAGovernment primary source
NSA
Supports: Release date, adoption context and continuum-of-security framing
LReview status: Live check required. S190
FRAMEWORK2026Version v0.1 betaAuthoritative project source
OWASP Foundation
Supports: Community risk taxonomy; beta rather than final standard
DReview status: Durable. S191
STANDARD2025-01Version RFC 9700Formal standards source
IETF
Supports: OAuth security best current practice
DReview status: Durable. S192
STANDARD2022-03Version RFC 9207Formal standards source
IETF
Supports: Authorization-response issuer validation
DReview status: Durable. S193
STANDARD2012-10Version RFC 6750Formal standards source
IETF
Supports: Bearer-token transmission and challenge rules
DReview status: Durable. S194
STANDARD2015-07Version RFC 7591Formal standards source
IETF
Supports: Historical DCR mechanism now deprecated by current MCP
DReview status: Durable. S195
SECURITY RESEARCH2025-04-07Version Session-era clientsOriginal research
Invariant Labs
Supports: Practical cross-server/rug-pull demonstration
PReview status: Periodic review. S196
PREPRINT2026-05-21Version Servers measured before 2026-07-28Primary research preprint
Zhou et al.
Supports: 7,973 live servers, authentication distribution, 119-server OAuth subset and nine CVEs; preprint with selection limits
Evidence note: Do not generalize OAuth flaw rates beyond the testable subset.
PReview status: Periodic review. S197
PREPRINT2026-05-20Version 2025-2026 ecosystemPrimary research preprint
VIPER-MCP authors
Supports: Large-scale repository audit; 106 confirmed findings and 67 CVEs as reported by authors
Evidence note: Preprint statistics require method and version qualification.
DReview status: Durable. S198
PEER REVIEW/PREPRINT2026-03-23Version Clients tested in 2025/2026Peer-reviewed research
Huang et al.
Supports: STRIDE/DREAD model and seven-client tool-poisoning evaluation
PReview status: Periodic review. S199
PREPRINT2026-03-18Version 2026 taxonomyPrimary research preprint
Shen, Toyoda and Leung
Supports: 38-category MCP threat taxonomy
PReview status: Periodic review. S200
PREPRINT2025-12-06Version 2025 clients/modelsPrimary research preprint
Jamshidi et al.
Supports: Tool poisoning, shadowing, rug pulls and layered defense evaluation
PReview status: Periodic review. S201
PREPRINT2026-01-12Version 2026 benchmarkPrimary research preprint
Li et al.
Supports: Implicit tool poisoning and adaptive attack study
PReview status: Periodic review. S202
PREPRINT2026-06-25Version 2026 clientsPrimary research preprint
Liu et al.
Supports: Multi-tool threshold poisoning research
PReview status: Periodic review. S203
PREPRINT2026-04-18Version 2026 defense studyPrimary research preprint
Turgut and Gümüş
Supports: Prompt-injection detector evaluation and limitations
PReview status: Periodic review. S204
PREPRINT2026-08-01Version July 2026 scansPrimary research preprint
Corvus study author
Supports: Dynamic audit of internet-facing servers; reported exposure and churn figures
Evidence note: Very recent preprint; preserve methodology caveats.
LReview status: Live check required. S205
SECURITY ADVISORY2025-07-04Version <1.9.4Vendor advisory / CVE
MCP Python SDK
Supports: Validation error amplification / denial of service; patched/fixed status: 1.9.4
Evidence note: Layer: SDK. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S206
SECURITY ADVISORY2025-07-04Version <1.10.0Vendor advisory / CVE
MCP Python SDK
Supports: Closed-resource handling denial of service; patched/fixed status: 1.10.0
Evidence note: Layer: SDK. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S207
SECURITY ADVISORY2026-02-20Version <1.4.0Vendor advisory / CVE
MCP Go SDK
Supports: DNS rebinding protection gap for localhost HTTP servers; patched/fixed status: 1.4.0
Evidence note: Layer: SDK/transport. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S208
SECURITY ADVISORY2026-02-26Version <1.0.0Vendor advisory / CVE
MCP Java SDK
Supports: DNS rebinding protection gap for localhost HTTP servers; patched/fixed status: 1.0.0
Evidence note: Layer: SDK/transport. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S209
SECURITY ADVISORY2026-04-14Version <1.4.0Vendor advisory / CVE
MCP Rust SDK
Supports: DNS rebinding protection gap; patched/fixed status: 1.4.0
Evidence note: Layer: SDK/transport. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S210
SECURITY ADVISORY2026-06-08Version <=0.22.0Vendor advisory / CVE
MCP Ruby SDK
Supports: DNS rebinding protection gap; patched/fixed status: 0.23.0
Evidence note: Layer: SDK/transport. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S211
SECURITY ADVISORY2026-06-24Version <=0.22.0Vendor advisory / CVE
MCP Ruby SDK
Supports: Protocol-session poisoning / state confusion in legacy session architecture; patched/fixed status: 0.23.0
Evidence note: Layer: SDK/session. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S212
SECURITY ADVISORY2026-06-24Version LIVE-CHECK REQUIREDVendor advisory / CVE
MCP Ruby SDK
Supports: Unbounded stdio message handling can exhaust resources; patched/fixed status: 0.23.0 reported
Evidence note: Layer: SDK/stdio. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S213
SECURITY ADVISORY2026-06-24Version LIVE-CHECK REQUIREDVendor advisory / CVE
MCP Ruby SDK
Supports: Legacy session retention / cleanup flaw; patched/fixed status: 0.23.0 reported
Evidence note: Layer: SDK/session. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S214
SECURITY ADVISORY2026-01-08Version <1.25.2Vendor advisory / CVE
MCP TypeScript SDK
Supports: UriTemplate regular-expression denial of service; patched/fixed status: 1.25.2
Evidence note: Layer: SDK/parser. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S215
SECURITY ADVISORY2025-10-16Version <2025.9.25Vendor advisory / CVE
MCP reference Git server
Supports: Repository path validation weakness; patched/fixed status: 2025.9.25 / server removed
Evidence note: Layer: Server implementation. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S216
SECURITY ADVISORY2026-04-29Version <1.7.7Vendor advisory / CVE
Official MCP Registry
Supports: Server-side request forgery in registry processing; patched/fixed status: 1.7.7
Evidence note: Layer: Registry. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S217
SECURITY ADVISORY2026-04-29Version <1.7.6Vendor advisory / CVE
Official MCP Registry
Supports: OIDC token replay / validation flaw; patched/fixed status: 1.7.6
Evidence note: Layer: Registry/auth. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S218
SECURITY ADVISORY2026-04-29Version >=1.1.0,<1.7.5Vendor advisory / CVE
Official MCP Registry
Supports: Open redirect; patched/fixed status: 1.7.5
Evidence note: Layer: Registry/web. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S219
SECURITY ADVISORY2026-05-01Version LIVE-CHECK REQUIREDVendor advisory / CVE
Official MCP Registry
Supports: Stored cross-site scripting; patched/fixed status: LIVE-CHECK REQUIRED
Evidence note: Layer: Registry/web. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S220
SECURITY ADVISORY2026-05-01Version <1.7.9Vendor advisory / CVE
Official MCP Registry
Supports: OCI verification fail-open behavior; patched/fixed status: 1.7.9
Evidence note: Layer: Registry/supply chain. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S221
SECURITY ADVISORY2025-08-29Version <0.0.40Vendor advisory / CVE
Microsoft Playwright MCP
Supports: DNS rebinding against localhost HTTP mode; patched/fixed status: 0.0.40
Evidence note: Layer: Server/transport. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S222
SECURITY ADVISORY2026-08-07Version <1.2.0Vendor advisory / CVE
Google MCP Toolbox for Databases
Supports: DNS rebinding in legacy SSE/local deployment; patched/fixed status: 1.2.0
Evidence note: Layer: Server/transport. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S223
SECURITY ADVISORY2026-03-03Version <0.17.0Vendor advisory / CVE
CircleCI MCP Server
Supports: DNS rebinding protection weakness; patched/fixed status: 0.17.0
Evidence note: Layer: Server/transport. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S224
SECURITY ADVISORY2026-01-16Version <=1.4.2Vendor advisory / CVE
MCPJam Inspector
Supports: Remote command execution; patched/fixed status: 1.4.3
Evidence note: Layer: Host/developer tool. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S225
SECURITY ADVISORY2026-04-03Version <3.2.0Vendor advisory / CVE
FastMCP
Supports: OAuth proxy callback missing consent binding; confused deputy; patched/fixed status: 3.2.0
Evidence note: Layer: Framework/auth. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S226
SECURITY ADVISORY2026-05-20Version <=3.0.1Vendor advisory / CVE
mcp-pinot
Supports: Network service bound broadly without authentication; patched/fixed status: 3.1.0
Evidence note: Layer: Server/deployment. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S227
SECURITY ADVISORY2026-04-20Version <1.1.0Vendor advisory / CVE
GitHub MCP Server
Supports: Nil-pointer denial of service; patched/fixed status: 1.1.0
Evidence note: Layer: Server implementation. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S228
SECURITY ADVISORY2026-05-16Version >=0.22.0,<1.1.2Vendor advisory / CVE
GitHub MCP Server
Supports: Lockdown mode cross-user authorization separation flaw; patched/fixed status: 1.1.2
Evidence note: Layer: Server/authorization. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S229
SECURITY ADVISORY2026-05-04Version <3.6.0Vendor advisory / CVE
Kubernetes MCP Server
Supports: Presentation-only authorization without server-side enforcement; patched/fixed status: 3.6.0
Evidence note: Layer: Server/authorization. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S230
SECURITY ADVISORY2026-05-29Version >=2.26.2,<2.26.4Vendor advisory / CVE
flyto-core
Supports: Unauthenticated command execution through MCP capability; patched/fixed status: 2.26.4
Evidence note: Layer: Server implementation. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S231
SECURITY ADVISORY2026-01-15Version <0.3.0Vendor advisory / CVE
MySQL MCP Server
Supports: SQL injection through insufficient input handling; patched/fixed status: 0.3.0
Evidence note: Layer: Server implementation. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S232
SECURITY ADVISORY2026-05-22Version <=1.7.0Vendor advisory / CVE
aws-mcp
Supports: Command injection; patched/fixed status: No patch listed when recorded
Evidence note: Layer: Server implementation. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S233
SECURITY ADVISORY2026-05-09Version <1.0.74Vendor advisory / CVE
Claude Code Action
Supports: Malicious repository .mcp.json can execute configured server code; patched/fixed status: 1.0.74
Evidence note: Layer: Host/project config. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S234
SECURITY ADVISORY2026-05-25Version <0.10.11Vendor advisory / CVE
Apify MCP Server
Supports: Path/token authorization weakness; patched/fixed status: 0.10.11
Evidence note: Layer: Server/authorization. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S235
SECURITY ADVISORY2026-03-24Version LIVE-CHECK REQUIREDVendor advisory / CVE
LibreChat
Supports: OAuth callback binding/account-linking weakness; patched/fixed status: 0.8.3-rc1 reported
Evidence note: Layer: Host/auth. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S236
SECURITY ADVISORY2026-03-26Version <=0.8.3Vendor advisory / CVE
LibreChat
Supports: Environment-expanded MCP URL can expose secrets; patched/fixed status: 0.8.4-rc1 reported
Evidence note: Layer: Host/configuration. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S237
SECURITY ADVISORY2026-03-26Version >=0.8.2-rc1,<=0.8.3-rc1Vendor advisory / CVE
LibreChat
Supports: Attacker-controlled headers can expose tokens; patched/fixed status: >=0.8.3-rc2
Evidence note: Layer: Host/auth. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S238
SECURITY ADVISORY2026-04-01Version <4.5.128Vendor advisory / CVE
PraisonAI
Supports: Environment variables inherited by local MCP processes; patched/fixed status: 4.5.128
Evidence note: Layer: Host/local process. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S239
SECURITY ADVISORY2026-04-10Version <=4.5.148Vendor advisory / CVE
PraisonAI
Supports: Unsafe command parsing for MCP server configuration; patched/fixed status: Patched after 4.5.148
Evidence note: Layer: Host/local process. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S240
SECURITY ADVISORY2026-06-01Version <=4.6.48Vendor advisory / CVE
PraisonAI
Supports: Unauthenticated remote MCP connect path; patched/fixed status: 4.6.59
Evidence note: Layer: Host/network. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S241
SECURITY ADVISORY2026-05-12Version <=4.6.39Vendor advisory / CVE
PraisonAI
Supports: Arbitrary local file read through MCP integration; patched/fixed status: 4.6.40
Evidence note: Layer: Host/server. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S242
SECURITY ADVISORY2026-03-15Version <=2.3.3 reportedVendor advisory / CVE
Nginx UI MCP integration
Supports: Unauthenticated MCP endpoint enabling administrative takeover; patched/fixed status: 2.3.4 reported
Evidence note: Layer: Server/product integration. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S243
SECURITY ADVISORY2025-07-09Version LIVE-CHECK REQUIREDVendor advisory / CVE
mcp-remote
Supports: Command injection in remote-server launcher; patched/fixed status: LIVE-CHECK REQUIRED
Evidence note: Layer: Launcher/supply chain. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S244
SECURITY ADVISORY2026-01-23Version >=1.0.16 malicious seriesVendor advisory / CVE
Postmark MCP impersonator
Supports: Malicious npm package impersonating an official server and exfiltrating API keys; patched/fixed status: Remove package; use verified vendor source
Evidence note: Layer: Supply chain. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S245
SECURITY ADVISORY2025-09-17Version Before 2025.09.17-25b418fVendor advisory / CVE
Cursor
Supports: Malicious project MCP configuration can trigger code execution; patched/fixed status: 2025.09.17-25b418f
Evidence note: Layer: Host/project config. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S246
SECURITY ADVISORY2025-12-19Version <0.218.2-preVendor advisory / CVE
Zed
Supports: Malicious project MCP configuration can trigger code execution; patched/fixed status: 0.218.2-pre
Evidence note: Layer: Host/project config. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S247
SECURITY ADVISORY2026-04-22Version <=2026.4.21Vendor advisory / CVE
OpenClaw
Supports: Owner identity spoofing in MCP-connected workflow; patched/fixed status: 2026.4.22
Evidence note: Layer: Host/identity. Verify current affected and fixed ranges before publication.
LReview status: Live check required. S248
SECURITY POLICY2026Version CurrentOfficial repository
Model Context Protocol
Supports: Vulnerability reporting and scope
DReview status: Durable. S249
SPEC2024-11-05Version 2024-11-05Primary or first-party source
Model Context Protocol
Supports: Launch-era host, client and server roles and stateful capability-negotiated architecture.
Evidence note: Normalized from the checksum-verified research/5 architecture package.
DReview status: Durable. S250
SPEC2024-11-05Version 2024-11-05Primary or first-party source
Model Context Protocol
Supports: Launch-era protocol layering and absence of the later core authorization framework.
Evidence note: Normalized from the checksum-verified research/5 architecture package.
DReview status: Durable. S251
SPEC2025-06-18Version 2025-06-18Primary or first-party source
Model Context Protocol
Supports: Legacy architecture: host manages clients; each client maintains a stateful session with one server; isolation principles.
Evidence note: Normalized from the checksum-verified research/5 architecture package.
LReview status: Live check required. S252
SDK DOC2026-07-28Version 2026-07-28Primary or first-party source
Model Context Protocol
Supports: Official TypeScript SDK v2 support for current MCP and examples of hosts connecting to servers.
Evidence note: Normalized from the checksum-verified research/5 architecture package.
LReview status: Live check required. S253
SDK DOC2026-07-28Version 2026-07-28Primary or first-party source
Model Context Protocol
Supports: Modern versus legacy protocol eras and automatic compatibility behavior.
Evidence note: Normalized from the checksum-verified research/5 architecture package.
LReview status: Live check required. S254
SDK DOC2026-07-28Version 2026-07-28Primary or first-party source
Model Context Protocol
Supports: Official SDK handling of both legacy and current protocol eras.
Evidence note: Normalized from the checksum-verified research/5 architecture package.
LReview status: Live check required. S255
SDK DOC2026-07-28Version 2026-07-28Primary or first-party source
Model Context Protocol
Supports: Current connection behavior without an initialization handshake.
Evidence note: Normalized from the checksum-verified research/5 architecture package.
LReview status: Live check required. S256
SDK DOC2026-07-28Version CurrentPrimary or first-party source
Model Context Protocol
Supports: Official Java client implementation responsibilities and transports.
Evidence note: Normalized from the checksum-verified research/5 architecture package.
LReview status: Live check required. S257
SDK DOC2026-07-28Version CurrentPrimary or first-party source
Model Context Protocol
Supports: Official Java server implementation responsibilities and capabilities.
Evidence note: Normalized from the checksum-verified research/5 architecture package.
LReview status: Live check required. S258
VENDOR DOC2026-08-25Version Current product statePrimary or first-party source
Anthropic
Supports: Anthropic distinguishes local desktop extensions from cloud-brokered remote connectors across supported Claude surfaces.
Evidence note: Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.
LReview status: Live check required. S259
VENDOR DOC2026-08-25Version Current product statePrimary or first-party source
Anthropic
Supports: Claude Code as an MCP host/client and optional MCP server through claude mcp serve.
Evidence note: Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.
LReview status: Live check required. S260
VENDOR DOC2026-06-30Version Current product statePrimary or first-party source
Anthropic
Supports: Claude Desktop local server configuration and management.
Evidence note: Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.
LReview status: Live check required. S261
DOCS2026-08-25Version Live documentation checked 2026-08-25Primary or first-party source
OpenAI
Supports: Supported private, on-premises, and developer-machine MCP servers can be exposed to ChatGPT through Secure MCP Tunnel.
Evidence note: Added during the 2026-08-25 first-party product-source review; not part of the byte-exact research/5 archive.
LReview status: Live check required. S262
VENDOR RELEASE2025-06-04Version Historical adoptionPrimary or first-party source
OpenAI
Supports: Initial ChatGPT custom connector support through remote MCP.
Evidence note: Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.
LReview status: Live check required. S263
VENDOR RELEASE2025-03-01Version Historical adoptionPrimary or first-party source
Microsoft
Supports: Initial VS Code MCP support in agent mode.
Evidence note: Normalized from the checksum-verified research/5 architecture package.
LReview status: Live check required. S264
VENDOR BLOG2026-05-15Version Current architecture contextPrimary or first-party source
Microsoft
Supports: Agent harness responsibilities: context, model loop, tool calls and execution coordination.
Evidence note: Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.
LReview status: Live check required. S265
VENDOR DOC2026-08-25Version Current product statePrimary or first-party source
GitHub
Supports: GitHub Copilot cloud agent can use tools from configured MCP servers, subject to its documented capability, authentication, and approval limitations.
Evidence note: Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.
LReview status: Live check required. S266
VENDOR DOC2026-08-25Version Current product statePrimary or first-party source
GitHub
Supports: GitHub documents how to configure MCP servers for GitHub Copilot cloud agent.
Evidence note: Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.
LReview status: Live check required. S267
VENDOR DOC2026-08-25Version Current product statePrimary or first-party source
GitHub
Supports: Copilot Chat host/client behavior with a preconfigured GitHub MCP server and user approval.
Evidence note: Normalized from the checksum-verified research/5 architecture package.
LReview status: Live check required. S268
VENDOR DOC2026-08-25Version Current product statePrimary or first-party source
GitHub
Supports: Copilot CLI local and remote MCP server support.
Evidence note: Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.
LReview status: Live check required. S269
VENDOR DOC2026-08-25Version Current product statePrimary or first-party source
Cursor
Supports: Cursor as a host/client connecting to external MCP tools and data.
Evidence note: Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.
LReview status: Live check required. S270
DOCS2026-08-25Version Live documentation checked 2026-08-25Primary or first-party source
Microsoft
Supports: Microsoft Agent Host is a distinct AHP runtime or process and should not be confused with the MCP host role.
Evidence note: Added during the 2026-08-25 first-party product-source review; not part of the byte-exact research/5 archive.
LReview status: Live check required. S271
VENDOR DOC2026-08-25Version Current product statePrimary or first-party source
Google
Supports: Gemini CLI registration and use of Google-hosted MCP servers.
Evidence note: Normalized from the checksum-verified research/5 architecture package.
LReview status: Live check required. S272
VENDOR BLOG2025-12-17Version Current product/security statePrimary or first-party source
Zed Industries
Supports: Zed host behavior around project trust and automatic MCP server execution.
Evidence note: Normalized from the checksum-verified research/5 architecture package.
LReview status: Live check required. S273
VENDOR DOC2026-08-25Version Current product statePrimary or first-party source
Zed Industries
Supports: Host-level MCP tool allow, deny and confirm policy.
Evidence note: Normalized from the checksum-verified research/5 architecture package.
LReview status: Live check required. S274
VENDOR DOC2026-08-14Version AI Assistant 2026.2Primary or first-party source
JetBrains
Supports: JetBrains AI Assistant as MCP host/client; stdio, Streamable HTTP and legacy SSE support.
Evidence note: Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.
LReview status: Live check required. S275
VENDOR DOC2026-05-13Version PyCharm 2026.2Primary or first-party source
JetBrains
Supports: JetBrains IDEs as MCP servers exposing IDE tools to external clients.
Evidence note: Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.
LReview status: Live check required. S276
VENDOR KB2026-02-01Version Current product statePrimary or first-party source
JetBrains
Supports: Explicit distinction between JetBrains AI Assistant as client and the IDE as server.
Evidence note: Normalized from the checksum-verified research/5 architecture package.
LReview status: Live check required. S277
VENDOR DOC2026-08-03Version AI Assistant 2026.2Primary or first-party source
JetBrains
Supports: JetBrains host can pass configured MCP tools to several agent implementations.
Evidence note: Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.
PReview status: Periodic review. S278
COMPETITOR2026-08-25Version Search-result auditSecondary source
Tricentis
Supports: Competitor page retaining initialize-based legacy architecture; used only for SERP gap analysis.
Evidence note: Normalized from the checksum-verified research/5 architecture package.
PReview status: Periodic review. S279
COMPETITOR2026-08-25Version Search-result auditSecondary source
Stanza
Supports: Competitor page retaining initialization-centered architecture; used only for SERP gap analysis.
Evidence note: Normalized from the checksum-verified research/5 architecture package.
PReview status: Periodic review. S280
COMPETITOR2026-08-25Version Search-result auditSecondary source
MCP Server Spot
Supports: Competitor glossary using legacy session terminology; used only for SERP gap analysis.
Evidence note: Normalized from the checksum-verified research/5 architecture package.
LReview status: Live check required. S281
SEO GUIDANCE2025-12-10Version Current guidancePrimary or first-party source
Google Search Central
Supports: Unique title/meta, semantic HTML and DOM-accessible content.
Evidence note: Normalized from the checksum-verified research/5 architecture package.
LReview status: Live check required. S282
SEO GUIDANCE2025-12-10Version Current guidancePrimary or first-party source
Google Search Central
Supports: URL Inspection, sitemap submission and no guarantee of immediate indexing.
Evidence note: Normalized from the checksum-verified research/5 architecture package.
LReview status: Live check required. S283
DOCS2026-08-25Version Live documentation checked 2026-08-25Primary or first-party source
Cursor
Supports: Cursor CLI is a distinct MCP-consuming surface that shares MCP configuration with the Cursor editor.
Evidence note: Added during the 2026-08-25 first-party product-source review; not part of the byte-exact research/5 archive.
LReview status: Live check required. S284
DOCS2026-08-25Version Live documentation checked 2026-08-25Primary or first-party source
Zed Industries
Supports: Zed documents current MCP server configuration and its host-side MCP integration.
Evidence note: Added during the 2026-08-25 first-party product-source review; not part of the byte-exact research/5 archive.
LReview status: Live check required. S285
DOCS2026-08-25Version Live documentation checked 2026-08-25Primary or first-party source
Zed Industries
Supports: Restricted Mode blocks project-configured language and MCP servers until trust; globally configured servers are outside that gate.
Evidence note: Added during the 2026-08-25 first-party product-source review; not part of the byte-exact research/5 archive.
No records match those filters. Try a broader term.