<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:25:26 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-77267 — mcp-atlassian has an incomplete SSRF remediation</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-77267</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; sooperset mcp-atlassian&lt;/p&gt;
&lt;p&gt;MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url headers are processed by _process_authentication_headers and used to construct Atlassian fetchers without calling validate_url_for_ssrf. A caller who can set these headers can supply an internal or metadata-service URL and cause the server to send requests to that destination, bypassing the incomplete CVE-2026-27826 remediation. This issue is fixed in version 0.22.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; sooperset mcp-atlassian&lt;/p&gt;
&lt;p&gt;MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url headers are processed by _process_authentication_headers and used to construct Atlassian fetchers without calling validate_url_for_ssrf. A caller who can set these headers can supply an internal or metadata-service URL and cause the server to send requests to that destination, bypassing the incomplete CVE-2026-27826 remediation. This issue is fixed in version 0.22.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-77267</guid>
    </item>
    <item>
      <title>GHSA-5wf4-jqxh-8gm3 — mcp-atlassian has an incomplete SSRF remediation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5wf4-jqxh-8gm3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mcp-atlassian&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `UserTokenMiddleware` extracts URLs from `X-Atlassian-Jira-Url` and `X-Atlassian-Confluence-Url` HTTP headers and passes them directly to API client constructors without any SSRF validation.&lt;/p&gt;
&lt;p&gt;### Affected Package&lt;/p&gt;
&lt;p&gt;- **Ecosystem:** PyPI
- **Package:** mcp-atlassian
- **Affected versions:** all versions before fix commit 5cd697dfce91
- **Patched versions:** &amp;gt;= commit 5cd697dfce91&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;In `main.py`, `_process_authentication_headers()` extracts URLs from ASGI headers without validation. In `dependencies.py`, `get_jira_fetcher()` creates `JiraConfig` with `url=jira_url_header` directly. There is no `validate_url` call, no IP range check, no hostname validation.&lt;/p&gt;
&lt;p&gt;The fix adds URL validation to some paths but the header-based URL extraction in `_process_authentication_headers()` still passes raw URLs through. The derived config objects use the header URL directly and the fetcher makes HTTP requests to that URL.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;```python
jira_url_header = headers.get(b&amp;#34;x-atlassian-jira-url&amp;#34;)
jira_url_str = jira_url_header.decode(&amp;#34;latin-1&amp;#34;) if jira_url_header else None
service_headers[&amp;#34;X-Atlassian-Jira-Url&amp;#34;] = jira_url_str
```&lt;/p&gt;
&lt;p&gt;**Steps to reproduce:**
1. `git clone https://github.com/sooperset/mcp-atlassian /tmp/mcp-atlassian_test`
2. `cd /tmp/mcp-atlassian_test &amp;amp;&amp;amp; git checkout 5cd697dfce91~1`
3. `pip install -e .`
4. `python3 poc.py`&lt;/p&gt;
&lt;p&gt;**Expected output:**
```
VULNERABILITY CONFIRMED
User-supplied URLs from HTTP headers passed directly to JiraConfig/JiraFetcher wi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mcp-atlassian&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `UserTokenMiddleware` extracts URLs from `X-Atlassian-Jira-Url` and `X-Atlassian-Confluence-Url` HTTP headers and passes them directly to API client constructors without any SSRF validation.&lt;/p&gt;
&lt;p&gt;### Affected Package&lt;/p&gt;
&lt;p&gt;- **Ecosystem:** PyPI
- **Package:** mcp-atlassian
- **Affected versions:** all versions before fix commit 5cd697dfce91
- **Patched versions:** &amp;gt;= commit 5cd697dfce91&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;In `main.py`, `_process_authentication_headers()` extracts URLs from ASGI headers without validation. In `dependencies.py`, `get_jira_fetcher()` creates `JiraConfig` with `url=jira_url_header` directly. There is no `validate_url` call, no IP range check, no hostname validation.&lt;/p&gt;
&lt;p&gt;The fix adds URL validation to some paths but the header-based URL extraction in `_process_authentication_headers()` still passes raw URLs through. The derived config objects use the header URL directly and the fetcher makes HTTP requests to that URL.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;```python
jira_url_header = headers.get(b&amp;#34;x-atlassian-jira-url&amp;#34;)
jira_url_str = jira_url_header.decode(&amp;#34;latin-1&amp;#34;) if jira_url_header else None
service_headers[&amp;#34;X-Atlassian-Jira-Url&amp;#34;] = jira_url_str
```&lt;/p&gt;
&lt;p&gt;**Steps to reproduce:**
1. `git clone https://github.com/sooperset/mcp-atlassian /tmp/mcp-atlassian_test`
2. `cd /tmp/mcp-atlassian_test &amp;amp;&amp;amp; git checkout 5cd697dfce91~1`
3. `pip install -e .`
4. `python3 poc.py`&lt;/p&gt;
&lt;p&gt;**Expected output:**
```
VULNERABILITY CONFIRMED
User-supplied URLs from HTTP headers passed directly to JiraConfig/JiraFetcher wi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5wf4-jqxh-8gm3</guid>
    </item>
  </channel>
</rss>
