GHSA-89vp-x53w-74fx: rmcp Streamable HTTP server transport has a DNS rebinding vulnerability
- Identifiers
- CVE-2026-42559GHSA-89vp-x53w-74fx
- Published
- Record updated
- Affected
- rmcp < 1.4.0
- Fixed in
- 1.4.0
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.2%
Summary
Prior to version 1.4.0, the rmcp crate's Streamable HTTP server transport did not validate the incoming Host header, so a malicious public website using a DNS rebinding attack could send authenticated requests to a local or private-network MCP server. An attacker could enumerate and invoke exposed tools and read resources, and because MCP servers often run with the user's privileges, the impact can extend to arbitrary code execution on the victim's machine.
Mitigation
Fixed in rmcp 1.4.0 (PR #764, commit 8e22aa2): StreamableHttpServerConfig::allowed_hosts now defaults to a loopback-only allowlist, and requests whose Host header is not on the allowlist receive HTTP 403. Upgrade to rmcp >= 1.4.0. If upgrade is not possible, place the MCP server behind a reverse proxy configured to reject requests whose Host header is not an expected hostname, and do not bind the server to 0.0.0.0 without such a proxy.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- rmcpcrates.ioLLM dependency since 2025-03-16
Topics
Related items
- LowAnthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection FlawsSimilar attack · The Hacker News
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading