CVE-2026-30968
Coral Server has insufficient validation of agent identity for SSE connections
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The Internet of Agents. Prior to 1.1.0, the SSE endpoint (/sse/v1/...) in Coral Server did not strongly validate that a connecting agent was a legitimate participant in the session. This could theoretically allow unauthorized message injection or observation. This vulnerability is fixed in 1.1.0.
| CWE | CWE-862 |
| Vendor | coral-protocol |
| Product | coral-server |
| Published | Mar 10, 2026 |
| Last Updated | Mar 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for coral-protocol coral-server
Be the first to know when new unknown vulnerabilities affecting coral-protocol coral-server are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Coral-Protocol / coral-server
< 1.1.0