Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

mcp-go HTTP Host header validation vulnerability

mcp-go accepted HTTP requests without validating the Host header, allowing attackers to bypass loopback restrictions via DNS rebinding. The vulnerability was patched in version 0.56.0 by adding Host header validation.

Disclosed 27 August 2026 · Record updated 13 September 2026

Impact

Attackers could invoke tools and read resources on servers listening on loopback addresses by using DNS rebinding techniques.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-81092