Back

HIGH

mcp-go before 0.56.0 Missing Host Header Validation Enables DNS Rebinding

Published Aug 27, 2026

Description

mcp-go accepted requests on its HTTP transports without checking the Host header. StreamableHTTPServer.ServeHTTP in server/streamable_http.go and SSEServer.ServeHTTP in server/sse.go served any request arriving over a loopback connection regardless of the host it named, and the SSE transport's cross-origin default allowed any origin. A page in a browser could therefore point a name it controlled at the loopback address and reach a server listening there, invoking tools and reading resources that the server exposed on the assumption that only local software could connect. No release before 0.56.0 validated the header on either transport; 0.56.0 adds server/http_localhost.go, which rejects a loopback-bound request carrying a host that is not a loopback name, and wires it into both transports.

Affected products

Remediation

Red Hat statement

DNS rebinding requires a web browser executing JavaScript to run on the same host as the mcp-go HTTP server, with the user visiting a malicious page during that window. Red Hat products carrying this dependency are containerized server-side services (tempo, mcp-gateway) and CLI tools (rhai-cli) deployed in Kubernetes/OpenShift environments. In those deployments no browser shares the loopback interface with the affected service, so the preconditions for exploitation are not met. The high confidentiality and integrity scores in the CVSS vector reflect what a running mcp-go server can expose if the attack succeeds; in Red Hat deployments the co-located browser condition does not arise in normal operations.

Red Hat mitigation

Where an immediate update to mcp-go v0.56.0 is not possible: restrict inbound connections to known trusted clients via network policy or firewall rules, and place a reverse proxy in front of the MCP endpoint that enforces strict Host header validation.

Weaknesses (2)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 27, 2026
Updated Aug 29, 2026
Reserved Aug 26, 2026
CISA Vulnrichment
Updated Aug 27, 2026
NVD
Status Received
Modified Aug 28, 2026
Red Hat
Severity Moderate
Public date Aug 27, 2026
ENISA EUVD
Assigner VulnCheck
Published Aug 27, 2026
Updated Aug 29, 2026
Exploited since n/a
EUVD-2026-67147