MCP Atlassian releases before 0.22.0 fall back to the operator's credentials whenever an HTTP caller has no verified identity (CVE-2026-77244). HTTP deployments need the upgrade, and the endpoint should be reachable only through a management network or an authenticating proxy.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence40
A dev.to writeup pits Bifrost against LiteLLM on a shared four-core VPS, using the harness the Bifrost team maintains. The widest gap it reports traces back to a worker default the official LiteLLM image leaves unset.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+18
- Incentives68
- Confidence55
The Conflict detection attempts setting under IPv4 Advanced still defaults to 0 on Windows Server 2025 build 26100.33296. A packet capture from a sealed three-VM lab shows the offer leaving with no probe behind it.
Reality
- Evidence74
- Adoption
- Insufficient
- Hype gap+14
- Incentives22
- Confidence62
The patch for the last Gogs RCE validated the path parameter and never looked at where a committed symlink pointed. Wiz counted more than 700 already-compromised instances before v0.13.4 shipped.
Reality
- Evidence72
- Adoption74
- Hype gap+12
- Incentives68
- Confidence61
A table owner bypasses its own policies with no superuser rights and no BYPASSRLS, and one connection string makes the owner the serving role. Tests seeded with a single tenant never notice.
Reality
- Evidence74
- Adoption
- Insufficient
- Hype gap+14
- Incentives26
- Confidence68