8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
RMCP is an official Rust SDK for the Model Context Protocol. Prior to version 1.4.0, the rmcp crate's Streamable HTTP server transport (crates/rmcp/src/transport/streamable_http_server/) did not validate the incoming Host header. This allowed a malicious public website, via a DNS rebinding attack, to send authenticated requests to an MCP server running on the victim's loopback or private-network interface. This vulnerability is fixed in 1.4.0.
Basic Information
ID
CVE-2026-42559
Source
GitHub_M
Published
May 14, 2026 at 14:24
Modified
May 14, 2026 at 16:00
Affected Product
Vendor
modelcontextprotocol
Product
rust-sdk
Version
< 1.4.0
Affected Versions
modelcontextprotocol rust-sdk < 1.4.0
CWE Classification
References
- github.com /modelcontextprotocol/rust-sdk/security/advisories/GHSA-89vp-x53w-74fx
- github.com /modelcontextprotocol/rust-sdk/issues/815
- github.com /modelcontextprotocol/rust-sdk/issues/822
- github.com /modelcontextprotocol/rust-sdk/pull/764
- github.com /modelcontextprotocol/rust-sdk/commit/8e22aa2de28df5a285eed87c11cd89bf15fa90d3