{"data":{"id":"036c0023-2eb9-4366-8f0e-421ac8a79b43","title":"GHSA-9g45-5xwm-f3wc: RMCP: Custom HTTP headers leak to cross-origin redirect targets","summary":"The rmcp crate's StreamableHttpClientTransport forwards caller-supplied custom HTTP headers, such as X-API-Key, X-Auth-Token and Api-Key, to cross-origin redirect targets. The default_http_client() function sets no redirect policy override, so reqwest's default limited(10) policy follows 307/308 redirects and strips only Authorization, Cookie and Proxy-Authorization, leaving headers set through StreamableHttpClientTransportConfig.custom_headers intact. An attacker who controls a redirect target can capture those secrets, as tested at commit c330fede90e4729c234f8e87fdbc5ea27a1dd10c.","solution":"In default_http_client(), add .redirect(reqwest::redirect::Policy::none()) to the reqwest::Client builder so the transport can inspect 3xx responses and strip sensitive headers before following them. Alternatively, use reqwest::ClientBuilder::connection_verbose or per-request Request::headers_mut() to remove auth headers before the redirect is followed.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-9g45-5xwm-f3wc","publishedAt":"2026-09-17T14:48:12.000Z","cveId":"CVE-2026-64684","cweIds":["CWE-200"],"cvssScore":"6.8","cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":["rmcp@< 2.1.0 (fixed: 2.1.0)"],"affectedPackageNames":["rmcp"],"affectedPackageRefs":["cargo:rmcp"],"affectedVendors":["Anthropic"],"affectedVendorsRaw":["rmcp","MCP (Model Context Protocol) Rust SDK"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.005,"epssCheckedAt":"2026-10-10T04:57:26.722Z","kevDateAdded":null,"advisoryAliases":["GHSA-9g45-5xwm-f3wc"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-09-17T14:48:12.000Z","capecIds":["CAPEC-116"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.8,"researchCategory":null,"atlasIds":null}}