MCP Identity Gateway security updates
MCP Identity Gateway version 1.34.5794 includes security updates.
For the latest available versions of these components, see the Edge Components Supported Versions page.
MCP Identity Gateway version 1.34.5794 includes security updates.
For the latest available versions of these components, see the Edge Components Supported Versions page.
A security update for the MCP Identity Gateway broadens the MCP traffic that Content Security inspects.
The Gateway normalizes responses that MCP servers stream as server-sent events before inspection, so Content Security inspects those responses along with the rest of the session. The Gateway also applies the policy’s Fail Open on Error setting to requests it can’t read and to protocol errors. A policy set to fail closed blocks those requests.
These updates shipped in the same build as the MCP Identity Gateway 1.33.5654 release.
A security update for the MCP Identity Gateway advances two bundled third-party libraries to their latest patched releases, keeping the Gateway current with published advisories.
These updates shipped in the same build as the MCP Identity Gateway 1.33.5547 release.
MCP Identity Gateway now binds each session ID to the authenticated user, closing a privilege-escalation gap where one user’s session could carry over to another identity.
This change requires no configuration. It ships in MCP Identity Gateway 1.32.5098, alongside the workload event correlation and platform fixes in this build; see the event correlation and platform fixes entry.