mcp-go HTTP Host header validation vulnerability
mcp-go accepted HTTP requests without validating the Host header, allowing attackers to bypass loopback restrictions via DNS rebinding. The vulnerability was patched in version 0.56.0 by adding Host header validation.
Disclosed 27 August 2026 · Record updated 13 September 2026
Impact
Attackers could invoke tools and read resources on servers listening on loopback addresses by using DNS rebinding techniques.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-81092
