Toolhive
Stacklok · 4 CVEs
CVE-2026-58197
HIGH
ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement
Sep 18, 2026
CVE-2026-58196
LOW
ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation)
Sep 15, 2026
CVE-2026-54450
LOW
ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind…
Sep 15, 2026
CVE-2025-47274
LOW
ToolHive stores secrets in the state store with no encryption
May 12, 2025
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-58197 | ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement | HIGH | 0.37% | Sep 18, 2026 |
| CVE-2026-58196 | ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation) | LOW | 0.43% | Sep 15, 2026 |
| CVE-2026-54450 | ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway | LOW | 0.33% | Sep 15, 2026 |
| CVE-2025-47274 | ToolHive stores secrets in the state store with no encryption | LOW | 0.13% | May 12, 2025 |
Showing 1 to 4 of 4 CVEs