auth-fetch-mcp SSRF Protection Bypass via IPv6 Loopback
auth-fetch-mcp version 3.0.1 contains a Server-Side Request Forgery vulnerability where IPv4-mapped IPv6 loopback addresses bypass SSRF protection, allowing access to blocked loopback services. The issue was patched in version 3.0.1.
Disclosed 13 August 2026 · Record updated 13 September 2026
Impact
SSRF protection can be bypassed to reach loopback services that should be blocked under default configuration
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-49857
