Security
The posture, written down — including what it does not cover.
Hangar enforces deterministic policy on the MCP call path and records what happened. That draws a boundary, and a security page is only worth reading if it draws it honestly. These pages track the CVEs that matter to anyone running MCP servers, and map Hangar against the OWASP MCP Top 10 — marking the categories that are out of scope by design rather than claiming them.
Posture pages
- MCP ecosystem CVE ledgerPublished CVEs in the MCP ecosystem that matter to anyone running MCP servers behind Hangar — what each one is, and whether Hangar's controls relate to it. Including when they do not.Updated Aug 9, 2026
- OWASP MCP Top 10 coverageWhere MCP Hangar maps against the OWASP MCP Top 10 (2025) — what it enforces, which component does it, and the three categories that are out of scope by design.Updated Aug 9, 2026
Advisories
All postsEvery advisory is published in full on the blog. The ledger summarises and links to them — it does not replace them.
Reporting a vulnerability
Found something in Hangar itself? The disclosure process — where to send it and what to expect — is in the docs. Please do not open a public issue for a security report.
Security policy & disclosure