<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:31:01 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-42559 — RMCP: DNS rebinding vulnerability in rmcp Streamable HTTP server transport</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-42559</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; modelcontextprotocol rust-sdk&lt;/p&gt;
&lt;p&gt;RMCP is an official Rust SDK for the Model Context Protocol. Prior to version 1.4.0, the rmcp crate&amp;#39;s Streamable HTTP server transport (crates/rmcp/src/transport/streamable_http_server/) did not validate the incoming Host header. This allowed a malicious public website, via a DNS rebinding attack, to send authenticated requests to an MCP server running on the victim&amp;#39;s loopback or private-network interface. This vulnerability is fixed in 1.4.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; modelcontextprotocol rust-sdk&lt;/p&gt;
&lt;p&gt;RMCP is an official Rust SDK for the Model Context Protocol. Prior to version 1.4.0, the rmcp crate&amp;#39;s Streamable HTTP server transport (crates/rmcp/src/transport/streamable_http_server/) did not validate the incoming Host header. This allowed a malicious public website, via a DNS rebinding attack, to send authenticated requests to an MCP server running on the victim&amp;#39;s loopback or private-network interface. This vulnerability is fixed in 1.4.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-42559</guid>
    </item>
    <item>
      <title>GHSA-89vp-x53w-74fx — rmcp Streamable HTTP server transport has a DNS rebinding vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-89vp-x53w-74fx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: rmcp&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Prior to version 1.4.0, the `rmcp` crate&amp;#39;s Streamable HTTP server transport (`crates/rmcp/src/transport/streamable_http_server/`) did not validate the incoming `Host` header. This allowed a malicious public website, via a DNS rebinding attack, to send authenticated requests to an MCP server running on the victim&amp;#39;s loopback or private-network interface — violating the MCP specification&amp;#39;s [transport security guidance](https://modelcontextprotocol.io/specification/2025-06-18/basic/transports#security-warning).&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker who convinces a victim to visit a malicious page can:&lt;/p&gt;
&lt;p&gt;- Enumerate and invoke any tool exposed by a locally-running rmcp-based MCP server.
- Read resources, prompts, and any state accessible via the MCP session.
- Trigger side effects (file writes, shell execution, API calls, etc.) limited only by what tools the victim&amp;#39;s server exposes.&lt;/p&gt;
&lt;p&gt;Because MCP servers frequently run with the user&amp;#39;s privileges and expose developer tooling (filesystems, shells, browser control, language servers, etc.), the practical impact can extend to arbitrary code execution on the victim&amp;#39;s machine.&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;`rmcp &amp;lt; 1.4.0` — all prior releases of the Streamable HTTP server transport. Non-HTTP transports (stdio, child-process) are not affected.&lt;/p&gt;
&lt;p&gt;## Patched Versions&lt;/p&gt;
&lt;p&gt;`rmcp &amp;gt;= 1.4.0` (current: 1.5.1).&lt;/p&gt;
&lt;p&gt;## Patch&lt;/p&gt;
&lt;p&gt;Fixed in [PR #764](https://github.com/modelcontextprotocol/rust-sdk/pull/764) (commit `8e22aa2`), released as v1.4.0 on 2026-04-09:&lt;/p&gt;
&lt;p&gt;- `Stream…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: rmcp&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Prior to version 1.4.0, the `rmcp` crate&amp;#39;s Streamable HTTP server transport (`crates/rmcp/src/transport/streamable_http_server/`) did not validate the incoming `Host` header. This allowed a malicious public website, via a DNS rebinding attack, to send authenticated requests to an MCP server running on the victim&amp;#39;s loopback or private-network interface — violating the MCP specification&amp;#39;s [transport security guidance](https://modelcontextprotocol.io/specification/2025-06-18/basic/transports#security-warning).&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker who convinces a victim to visit a malicious page can:&lt;/p&gt;
&lt;p&gt;- Enumerate and invoke any tool exposed by a locally-running rmcp-based MCP server.
- Read resources, prompts, and any state accessible via the MCP session.
- Trigger side effects (file writes, shell execution, API calls, etc.) limited only by what tools the victim&amp;#39;s server exposes.&lt;/p&gt;
&lt;p&gt;Because MCP servers frequently run with the user&amp;#39;s privileges and expose developer tooling (filesystems, shells, browser control, language servers, etc.), the practical impact can extend to arbitrary code execution on the victim&amp;#39;s machine.&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;`rmcp &amp;lt; 1.4.0` — all prior releases of the Streamable HTTP server transport. Non-HTTP transports (stdio, child-process) are not affected.&lt;/p&gt;
&lt;p&gt;## Patched Versions&lt;/p&gt;
&lt;p&gt;`rmcp &amp;gt;= 1.4.0` (current: 1.5.1).&lt;/p&gt;
&lt;p&gt;## Patch&lt;/p&gt;
&lt;p&gt;Fixed in [PR #764](https://github.com/modelcontextprotocol/rust-sdk/pull/764) (commit `8e22aa2`), released as v1.4.0 on 2026-04-09:&lt;/p&gt;
&lt;p&gt;- `Stream…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-89vp-x53w-74fx</guid>
    </item>
    <item>
      <title>RUSTSEC-2026-0189 — DNS rebinding vulnerability in rmcp Streamable HTTP server transport</title>
      <link>https://cve.radiocsirt.org/vuln/rustsec-2026-0189</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: rmcp&lt;/p&gt;
&lt;p&gt;Prior to version 1.4.0, the `rmcp` crate&amp;#39;s Streamable HTTP server transport did
not validate the incoming `Host` header.&lt;/p&gt;
&lt;p&gt;This allowed a malicious public website, via a DNS rebinding attack, to send
requests to an MCP server running on the victim&amp;#39;s loopback or private-network
interface.&lt;/p&gt;
&lt;p&gt;An attacker who convinced a victim to visit a malicious page could enumerate and
invoke tools exposed by a locally running rmcp-based MCP server, read resources
and prompts, and trigger side effects limited by the tools exposed by that
server.&lt;/p&gt;
&lt;p&gt;Non-HTTP transports such as stdio and child-process transports are not affected.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;The issue was fixed in `rmcp` 1.4.0 by adding default loopback-only host
allowlist validation for the Streamable HTTP server transport. Incoming HTTP
requests now validate the `Host` header and return HTTP 403 when the host is not
allowed.&lt;/p&gt;
&lt;p&gt;Users should upgrade to `rmcp &amp;gt;= 1.4.0`.&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;If upgrading is not possible, place the MCP server behind a reverse proxy
configured to reject requests whose `Host` header is not one of the expected
hostnames. Do not bind the MCP server to `0.0.0.0` without such validation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: rmcp&lt;/p&gt;
&lt;p&gt;Prior to version 1.4.0, the `rmcp` crate&amp;#39;s Streamable HTTP server transport did
not validate the incoming `Host` header.&lt;/p&gt;
&lt;p&gt;This allowed a malicious public website, via a DNS rebinding attack, to send
requests to an MCP server running on the victim&amp;#39;s loopback or private-network
interface.&lt;/p&gt;
&lt;p&gt;An attacker who convinced a victim to visit a malicious page could enumerate and
invoke tools exposed by a locally running rmcp-based MCP server, read resources
and prompts, and trigger side effects limited by the tools exposed by that
server.&lt;/p&gt;
&lt;p&gt;Non-HTTP transports such as stdio and child-process transports are not affected.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;The issue was fixed in `rmcp` 1.4.0 by adding default loopback-only host
allowlist validation for the Streamable HTTP server transport. Incoming HTTP
requests now validate the `Host` header and return HTTP 403 when the host is not
allowed.&lt;/p&gt;
&lt;p&gt;Users should upgrade to `rmcp &amp;gt;= 1.4.0`.&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;If upgrading is not possible, place the MCP server behind a reverse proxy
configured to reject requests whose `Host` header is not one of the expected
hostnames. Do not bind the MCP server to `0.0.0.0` without such validation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rustsec-2026-0189</guid>
    </item>
  </channel>
</rss>
