GHSA-9g45-5xwm-f3wc: RMCP: Custom HTTP headers leak to cross-origin redirect targets
- Identifiers
- CVE-2026-64684GHSA-9g45-5xwm-f3wc
- Published
- Record updated
- Affected
- rmcp < 2.1.0
- Fixed in
- 2.1.0
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.5%
Summary
The rmcp crate's StreamableHttpClientTransport forwards caller-supplied custom HTTP headers, such as X-API-Key, X-Auth-Token and Api-Key, to cross-origin redirect targets. The default_http_client() function sets no redirect policy override, so reqwest's default limited(10) policy follows 307/308 redirects and strips only Authorization, Cookie and Proxy-Authorization, leaving headers set through StreamableHttpClientTransportConfig.custom_headers intact. An attacker who controls a redirect target can capture those secrets, as tested at commit c330fede90e4729c234f8e87fdbc5ea27a1dd10c.
Mitigation
In default_http_client(), add .redirect(reqwest::redirect::Policy::none()) to the reqwest::Client builder so the transport can inspect 3xx responses and strip sensitive headers before following them. Alternatively, use reqwest::ClientBuilder::connection_verbose or per-request Request::headers_mut() to remove auth headers before the redirect is followed.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- rmcpcrates.ioLLM dependency since 2025-03-16
Related items
- HighCVE-2026-101998: Docker Sandboxes fail open when masking credentials in proxy responsesSame vendor · NVD/CVE Database
- HighCVE-2026-103435: Claude Code symlink race condition allows writes outside project directorySame vendor · NVD/CVE Database
- HighGHSA-6qxp-vccf-f47h: MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP serverSame vendor · GitHub Advisory Database
- HighCVE-2026-103012: Claude Code stored API key overrides organization policy sign-inSame vendor · NVD/CVE Database
- HighCVE-2026-100585: OpenClaw permission prompt approval bypass through MCP channel bridgeSame vendor · NVD/CVE Database