mcp-go before 0.56.0 Missing Host Header Validation Enables DNS Rebinding
Published Aug 27, 2026
7.6
HIGHCVSS 4.0
EPSS 0.22%
Description
mcp-go accepted requests on its HTTP transports without checking the Host header. StreamableHTTPServer.ServeHTTP in server/streamable_http.go and SSEServer.ServeHTTP in server/sse.go served any request arriving over a loopback connection regardless of the host it named, and the SSE transport's cross-origin default allowed any origin. A page in a browser could therefore point a name it controlled at the loopback address and reach a server listening there, invoking tools and reading resources that the server exposed on the assumption that only local software could connect. No release before 0.56.0 validated the header on either transport; 0.56.0 adds server/http_localhost.go, which rejects a loopback-bound request carrying a host that is not a loopback name, and wires it into both transports.
Affected products
-
- Version 0StatusaffectedConstraints<0.56.0
- Version
No data.
No data.
Red Hat Hardened Images
tempo2-10-main-2.10.8-0.2.hum1
Fixed · RHSA-2026:62527
Red Hat Hardened Images
tempo3-0-main-3.0.3-0.1.hum1
Fixed · RHSA-2026:54874
Red Hat Hardened Images
tempo3-0-main-3.0.3-0.2.hum1
Fixed · RHSA-2026:62537
Red Hat Connectivity Link 1
rhcl-tech-preview/mcp-gateway-rhel9
Fix deferred
Red Hat Connectivity Link 1
rhcl-tech-preview/mcp-gateway-rhel9-operator
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/rhai-cli-rhel9
Fix deferred
Red Hat OpenShift distributed tracing 3
rhosdt/tempo-query-rhel9
Fix deferred
Red Hat OpenShift distributed tracing 3
rhosdt/tempo-rhel9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | tempo2-10-main-2.10.8-0.2.hum1 | Fixed | RHSA-2026:62527 |
| Red Hat Hardened Images | tempo3-0-main-3.0.3-0.1.hum1 | Fixed | RHSA-2026:54874 |
| Red Hat Hardened Images | tempo3-0-main-3.0.3-0.2.hum1 | Fixed | RHSA-2026:62537 |
| Red Hat Connectivity Link 1 | rhcl-tech-preview/mcp-gateway-rhel9 | Fix deferred | n/a |
| Red Hat Connectivity Link 1 | rhcl-tech-preview/mcp-gateway-rhel9-operator | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/rhai-cli-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift distributed tracing 3 | rhosdt/tempo-query-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift distributed tracing 3 | rhosdt/tempo-rhel9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
DNS rebinding requires a web browser executing JavaScript to run on the same host as the mcp-go HTTP server, with the user visiting a malicious page during that window. Red Hat products carrying this dependency are containerized server-side services (tempo, mcp-gateway) and CLI tools (rhai-cli) deployed in Kubernetes/OpenShift environments. In those deployments no browser shares the loopback interface with the affected service, so the preconditions for exploitation are not met. The high confidentiality and integrity scores in the CVSS vector reflect what a running mcp-go server can expose if the attack succeeds; in Red Hat deployments the co-located browser condition does not arise in normal operations.
Red Hat mitigation
Where an immediate update to mcp-go v0.56.0 is not possible: restrict inbound connections to known trusted clients via network policy or firewall rules, and place a reverse proxy in front of the MCP endpoint that enforces strict Host header validation.
References (9)
- https://access.redhat.com/security/cve/CVE-2026-81092 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2525106 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-67147 Advisory
- https://github.com/mark3labs/mcp-go product
- https://github.com/mark3labs/mcp-go/pull/921 issue-trackingpatch
- https://github.com/mark3labs/mcp-go/releases/tag/v0.56.0 release-notes
- https://nvd.nist.gov/vuln/detail/CVE-2026-81092
- https://www.cve.org/CVERecord?id=CVE-2026-81092
- https://www.vulncheck.com/advisories/mcp-go-before-0.56.0-missing-host-header-validation-enables-dns-rebinding third-party-advisory
Change history (0)
No recorded changes yet.