Security Fixes
This patch release addresses two CVEs via dependency upgrades and one CodeQL finding via import cleanup.
Dependabot Alerts Closed
- CVE-2026-34073 —
cryptographybumped from 46.0.5 to 46.0.6: Fixes incomplete DNS name constraint enforcement for wildcard DNS SANs. Credit to Oleh Konko (1seal) for the report. Dependabot alert #68 (low severity). (#622) - CVE-2026-34043 —
serialize-javascriptbumped to >=7.0.5: Fixes CPU exhaustion DoS via crafted array-like objects. Affectstests/integration/andtests/web/npm packages. Dependabot alerts #66, #67 (medium severity). (#623)
CodeQL Cleanup
- CodeQL #379 — Removed unused
Optionalimport inharvester.py(note severity). No functional impact. (#623)
Maintenance
- Alphabetical sorting of dependencies in
pyproject.tomlfor improved readability and reduced merge conflicts. (#623)
Upgrade
pip install --upgrade mcp-memory-service
# or
uv add mcp-memory-service>=10.28.4No configuration changes required. This is a dependency-only patch.
Full Changelog
See CHANGELOG.md for complete version history.