{"data":{"id":"0102714c-ca59-49e9-b7a8-3b48686911fb","title":"GHSA-89vp-x53w-74fx: rmcp Streamable HTTP server transport has a DNS rebinding vulnerability","summary":"Prior to version 1.4.0, the rmcp crate's Streamable HTTP server transport did not validate the incoming Host header, so a malicious public website using a DNS rebinding attack could send authenticated requests to a local or private-network MCP server. An attacker could enumerate and invoke exposed tools and read resources, and because MCP servers often run with the user's privileges, the impact can extend to arbitrary code execution on the victim's machine.","solution":"Fixed in rmcp 1.4.0 (PR #764, commit 8e22aa2): StreamableHttpServerConfig::allowed_hosts now defaults to a loopback-only allowlist, and requests whose Host header is not on the allowlist receive HTTP 403. Upgrade to rmcp >= 1.4.0. If upgrade is not possible, place the MCP server behind a reverse proxy configured to reject requests whose Host header is not an expected hostname, and do not bind the server to 0.0.0.0 without such a proxy.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-89vp-x53w-74fx","publishedAt":"2026-05-06T21:55:56.000Z","cveId":"CVE-2026-42559","cweIds":["CWE-346","CWE-350"],"cvssScore":"8.8","cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["rmcp@< 1.4.0 (fixed: 1.4.0)"],"affectedPackageNames":["rmcp"],"affectedPackageRefs":["cargo:rmcp"],"affectedVendors":[],"affectedVendorsRaw":["rmcp","MCP (Model Context Protocol)"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0.00242,"epssCheckedAt":"2026-10-10T04:57:23.703Z","kevDateAdded":null,"advisoryAliases":["GHSA-89vp-x53w-74fx"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-05-06T21:55:56.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}