Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

auth-fetch-mcp SSRF Protection Bypass via IPv6 Loopback

auth-fetch-mcp version 3.0.1 contains a Server-Side Request Forgery vulnerability where IPv4-mapped IPv6 loopback addresses bypass SSRF protection, allowing access to blocked loopback services. The issue was patched in version 3.0.1.

Disclosed 13 August 2026 · Record updated 13 September 2026

Impact

SSRF protection can be bypassed to reach loopback services that should be blocked under default configuration

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-49857