This release includes 1 breaking change for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Affected surfaces
ReleasePort's take
Light signalThe MCP HTTP listener now restricts binding to localhost (127.0.0.1) only.
Why it matters: If your deployment relies on remote access to the MCP HTTP listener, connectivity will be blocked after upgrading to version 2486; plan for local‑only connections.
Summary
AI summaryMCP HTTP listener now only binds to localhost (127.0.0.1).
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Breaking | High |
Restricts MCP HTTP listener to bind only on localhost (127.0.0.1). Restricts MCP HTTP listener to bind only on localhost (127.0.0.1). Source: llm_adapter@2026-07-18 Confidence: high |
— |
Changelog
Restricted the MCP HTTP listener to 127.0.0.1; it no longer binds to all network interfaces.
Breaking Changes
- MCP HTTP listener restricted to bind only to 127.0.0.1; previously bound to all network interfaces.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Vehir
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]