<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:06:34 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-42559 — RMCP: DNS rebinding vulnerability in rmcp Streamable HTTP server transport</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-42559</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; modelcontextprotocol rust-sdk&lt;/p&gt;
&lt;p&gt;RMCP is an official Rust SDK for the Model Context Protocol. Prior to version 1.4.0, the rmcp crate&amp;#39;s Streamable HTTP server transport (crates/rmcp/src/transport/streamable_http_server/) did not validate the incoming Host header. This allowed a malicious public website, via a DNS rebinding attack, to send authenticated requests to an MCP server running on the victim&amp;#39;s loopback or private-network interface. This vulnerability is fixed in 1.4.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; modelcontextprotocol rust-sdk&lt;/p&gt;
&lt;p&gt;RMCP is an official Rust SDK for the Model Context Protocol. Prior to version 1.4.0, the rmcp crate&amp;#39;s Streamable HTTP server transport (crates/rmcp/src/transport/streamable_http_server/) did not validate the incoming Host header. This allowed a malicious public website, via a DNS rebinding attack, to send authenticated requests to an MCP server running on the victim&amp;#39;s loopback or private-network interface. This vulnerability is fixed in 1.4.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-42559</guid>
    </item>
    <item>
      <title>GHSA-89vp-x53w-74fx — rmcp Streamable HTTP server transport has a DNS rebinding vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-89vp-x53w-74fx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: rmcp&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Prior to version 1.4.0, the `rmcp` crate&amp;#39;s Streamable HTTP server transport (`crates/rmcp/src/transport/streamable_http_server/`) did not validate the incoming `Host` header. This allowed a malicious public website, via a DNS rebinding attack, to send authenticated requests to an MCP server running on the victim&amp;#39;s loopback or private-network interface — violating the MCP specification&amp;#39;s [transport security guidance](https://modelcontextprotocol.io/specification/2025-06-18/basic/transports#security-warning).&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker who convinces a victim to visit a malicious page can:&lt;/p&gt;
&lt;p&gt;- Enumerate and invoke any tool exposed by a locally-running rmcp-based MCP server.
- Read resources, prompts, and any state accessible via the MCP session.
- Trigger side effects (file writes, shell execution, API calls, etc.) limited only by what tools the victim&amp;#39;s server exposes.&lt;/p&gt;
&lt;p&gt;Because MCP servers frequently run with the user&amp;#39;s privileges and expose developer tooling (filesystems, shells, browser control, language servers, etc.), the practical impact can extend to arbitrary code execution on the victim&amp;#39;s machine.&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;`rmcp &amp;lt; 1.4.0` — all prior releases of the Streamable HTTP server transport. Non-HTTP transports (stdio, child-process) are not affected.&lt;/p&gt;
&lt;p&gt;## Patched Versions&lt;/p&gt;
&lt;p&gt;`rmcp &amp;gt;= 1.4.0` (current: 1.5.1).&lt;/p&gt;
&lt;p&gt;## Patch&lt;/p&gt;
&lt;p&gt;Fixed in [PR #764](https://github.com/modelcontextprotocol/rust-sdk/pull/764) (commit `8e22aa2`), released as v1.4.0 on 2026-04-09:&lt;/p&gt;
&lt;p&gt;- `Stream…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: rmcp&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Prior to version 1.4.0, the `rmcp` crate&amp;#39;s Streamable HTTP server transport (`crates/rmcp/src/transport/streamable_http_server/`) did not validate the incoming `Host` header. This allowed a malicious public website, via a DNS rebinding attack, to send authenticated requests to an MCP server running on the victim&amp;#39;s loopback or private-network interface — violating the MCP specification&amp;#39;s [transport security guidance](https://modelcontextprotocol.io/specification/2025-06-18/basic/transports#security-warning).&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker who convinces a victim to visit a malicious page can:&lt;/p&gt;
&lt;p&gt;- Enumerate and invoke any tool exposed by a locally-running rmcp-based MCP server.
- Read resources, prompts, and any state accessible via the MCP session.
- Trigger side effects (file writes, shell execution, API calls, etc.) limited only by what tools the victim&amp;#39;s server exposes.&lt;/p&gt;
&lt;p&gt;Because MCP servers frequently run with the user&amp;#39;s privileges and expose developer tooling (filesystems, shells, browser control, language servers, etc.), the practical impact can extend to arbitrary code execution on the victim&amp;#39;s machine.&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;`rmcp &amp;lt; 1.4.0` — all prior releases of the Streamable HTTP server transport. Non-HTTP transports (stdio, child-process) are not affected.&lt;/p&gt;
&lt;p&gt;## Patched Versions&lt;/p&gt;
&lt;p&gt;`rmcp &amp;gt;= 1.4.0` (current: 1.5.1).&lt;/p&gt;
&lt;p&gt;## Patch&lt;/p&gt;
&lt;p&gt;Fixed in [PR #764](https://github.com/modelcontextprotocol/rust-sdk/pull/764) (commit `8e22aa2`), released as v1.4.0 on 2026-04-09:&lt;/p&gt;
&lt;p&gt;- `Stream…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-89vp-x53w-74fx</guid>
    </item>
    <item>
      <title>RUSTSEC-2026-0140 — DNS rebinding and cross-origin CSRF in dynoxide's MCP HTTP transport</title>
      <link>https://cve.radiocsirt.org/vuln/rustsec-2026-0140</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: dynoxide-rs&lt;/p&gt;
&lt;p&gt;dynoxide&amp;#39;s MCP HTTP transport was vulnerable to DNS rebinding via its transitive `rmcp` dependency, plus a related cross-origin CSRF gap.&lt;/p&gt;
&lt;p&gt;A malicious web page could make the user&amp;#39;s browser send requests to a local `dynoxide mcp --http` or `dynoxide serve --mcp` server with a non-loopback `Host` header, which the server would then process. The Host check alone did not close a related cross-origin CSRF vector: a page could `fetch` the loopback endpoint with `mode: &amp;#39;no-cors&amp;#39;`, and the Host header would match while the Origin header went unchecked.&lt;/p&gt;
&lt;p&gt;Affected MCP write tools include `put_item`, `update_item`, `delete_item`, `create_table`, and `batch_write_item`.&lt;/p&gt;
&lt;p&gt;The stdio transport (`dynoxide mcp` without `--http`) is not affected.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;dynoxide 0.9.13 closes both vectors:&lt;/p&gt;
&lt;p&gt;- Upgrades `rmcp` from 1.1.1 to 1.6.0 (which ships a default Host-header allowlist).
- Sets explicit `allowed_hosts` and `allowed_origins` on `StreamableHttpServerConfig`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: dynoxide-rs&lt;/p&gt;
&lt;p&gt;dynoxide&amp;#39;s MCP HTTP transport was vulnerable to DNS rebinding via its transitive `rmcp` dependency, plus a related cross-origin CSRF gap.&lt;/p&gt;
&lt;p&gt;A malicious web page could make the user&amp;#39;s browser send requests to a local `dynoxide mcp --http` or `dynoxide serve --mcp` server with a non-loopback `Host` header, which the server would then process. The Host check alone did not close a related cross-origin CSRF vector: a page could `fetch` the loopback endpoint with `mode: &amp;#39;no-cors&amp;#39;`, and the Host header would match while the Origin header went unchecked.&lt;/p&gt;
&lt;p&gt;Affected MCP write tools include `put_item`, `update_item`, `delete_item`, `create_table`, and `batch_write_item`.&lt;/p&gt;
&lt;p&gt;The stdio transport (`dynoxide mcp` without `--http`) is not affected.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;dynoxide 0.9.13 closes both vectors:&lt;/p&gt;
&lt;p&gt;- Upgrades `rmcp` from 1.1.1 to 1.6.0 (which ships a default Host-header allowlist).
- Sets explicit `allowed_hosts` and `allowed_origins` on `StreamableHttpServerConfig`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rustsec-2026-0140</guid>
    </item>
  </channel>
</rss>
