Skip to content

UPinar/contrastapi

v1.34.5 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 24d MCP Security & Auth
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai-agents ai-security api claude claude-desktop-extension cve
+13 more
security domain-recon email-security llm-tools mcp mcpb mitre-atlas mitre-d3fend model-context-protocol osint sigma-rules threat-intelligence vulnerability-management

Affected surfaces

auth

Summary

AI summary

Updates Internal, multi-source, and Tests across a mixed release.

Full changelog

Keyless onboarding: per-identity IP grace

Replaces the per-(identity, tool) first-swipe exemption with a single 24h grace window per keyless identity. A new caller can now exercise every cost==1 MCP tool freely during the window instead of exhausting the shared hourly quota partway through a discovery pass; once the window elapses the identity falls back to the standard free hourly limit.

  • Composite (multi-source) tools, API-key callers, and REST requests are never graced.
  • IPv6 identities are bucketed to a /64; in-window traffic is metered against a separate high per-identity ceiling as a DoS backstop.
  • The window's start is recorded once and never reset.

Fixes

  • /welcome: the order_id query parameter is normalized to its canonical UUID form, making key lookups robust to non-canonical spellings (upper-case / braces / urn:) and closing a CodeQL log-injection alert on the render-failure path.

Internal

  • Tests: the first-swipe suite is replaced by a 22-case IP-grace suite; full suite 2602 passing.
  • MCP surface unchanged: 54 tools, 7 Resources, 3 Prompts.

Security Fixes

  • /welcome order_id normalization closes CodeQL log‑injection alert

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track UPinar/contrastapi

Get notified when new releases ship.

Sign up free

About UPinar/contrastapi

Security intelligence API with 31 MCP tools for CVE/EPSS/KEV lookup, domain recon (DNS/WHOIS/SSL/subdomains/CT logs), IOC/threat intel, OSINT (email/phone/username), and code security scanning (secrets, injection). Free 100 req/hr.

All releases →

Related context

Earlier breaking changes

  • v1.33.11 `bulk_sigma_rule_lookup` now costs 1 credit per `rule_id`, changing from flat 1 credit/call.

Beta — feedback welcome: [email protected]