<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:26:09.775734+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-77267</id>
    <title>CVE-2026-77267 — mcp-atlassian has an incomplete SSRF remediation</title>
    <updated>2026-10-02T23:26:09.777301+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> sooperset mcp-atlassian</p>
<p>MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url headers are processed by _process_authentication_headers and used to construct Atlassian fetchers without calling validate_url_for_ssrf. A caller who can set these headers can supply an internal or metadata-service URL and cause the server to send requests to that destination, bypassing the incomplete CVE-2026-27826 remediation. This issue is fixed in version 0.22.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-77267"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5wf4-jqxh-8gm3</id>
    <title>GHSA-5wf4-jqxh-8gm3 — mcp-atlassian has an incomplete SSRF remediation</title>
    <updated>2026-10-02T23:26:09.777355+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: mcp-atlassian</p>
<p>### Summary</p>
<p>The `UserTokenMiddleware` extracts URLs from `X-Atlassian-Jira-Url` and `X-Atlassian-Confluence-Url` HTTP headers and passes them directly to API client constructors without any SSRF validation.</p>
<p>### Affected Package</p>
<p>- **Ecosystem:** PyPI
- **Package:** mcp-atlassian
- **Affected versions:** all versions before fix commit 5cd697dfce91
- **Patched versions:** &gt;= commit 5cd697dfce91</p>
<p>### Details</p>
<p>In `main.py`, `_process_authentication_headers()` extracts URLs from ASGI headers without validation. In `dependencies.py`, `get_jira_fetcher()` creates `JiraConfig` with `url=jira_url_header` directly. There is no `validate_url` call, no IP range check, no hostname validation.</p>
<p>The fix adds URL validation to some paths but the header-based URL extraction in `_process_authentication_headers()` still passes raw URLs through. The derived config objects use the header URL directly and the fetcher makes HTTP requests to that URL.</p>
<p>### PoC</p>
<p>```python
jira_url_header = headers.get(b"x-atlassian-jira-url")
jira_url_str = jira_url_header.decode("latin-1") if jira_url_header else None
service_headers["X-Atlassian-Jira-Url"] = jira_url_str
```</p>
<p>**Steps to reproduce:**
1. `git clone https://github.com/sooperset/mcp-atlassian /tmp/mcp-atlassian_test`
2. `cd /tmp/mcp-atlassian_test &amp;&amp; git checkout 5cd697dfce91~1`
3. `pip install -e .`
4. `python3 poc.py`</p>
<p>**Expected output:**
```
VULNERABILITY CONFIRMED
User-supplied URLs from HTTP headers passed directly to JiraConfig/JiraFetcher wi…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5wf4-jqxh-8gm3"/>
  </entry>
</feed>
