Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Apollo MCP Server DNS rebinding flaw allows local tool invocation (CVE-2026-35577)

Apollo MCP Server before version 1.7.0 failed to validate the Host header on StreamableHTTP transport requests, allowing a malicious website to use DNS rebinding to reach a locally running MCP server and invoke its tools or access its resources on behalf of the user. The issue does not affect stdio transport and is fixed in version 1.7.0.

Disclosed 9 April 2026 · Record updated 13 September 2026

Impact

An attacker-controlled website could bypass same-origin policy via DNS rebinding to invoke MCP tools or access resources exposed by a localhost MCP server without authentication; no exploitation reported.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-35577