216.73.217.22

CVE-2026-42559

· Published 14/05/2026 15:16 · Modified 14/05/2026 17:19

Labels: CVE-2026-42559 2026-05-14CVE-2026-42559CWE-346[email protected]

Essential information

Published
14/05/2026 15:16
Modified
14/05/2026 17:19
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

RMCP is an official Rust SDK for the Model Context Protocol. Prior to version 1.4.0, the rmcp crate's Streamable HTTP server transport (crates/rmcp/src/transport/streamable_http_server/) did not validate the incoming Host header. This allowed a malicious public website, via a DNS rebinding attack, to send authenticated requests to an MCP server running on the victim's loopback or private-network interface. This vulnerability is fixed in 1.4.0.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
rust / rmcp cpe:2.3:a:rust:rmcp:*:*:*:*:*:*:*:*

References