GHSA-xw59-hvm2-8pj6
HIGHCVE-2026-34742The Model Context Protocol (MCP) Go SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on localhost without authentication with StreamableHTTPHandler or SSEHandler, a malicious website could exploit DNS rebinding to bypass same-origin policy restrictions and send requests to the local MCP server. This could allow an attacker to invo
- Affected
- < 1.4.0
- Fixed in
- 1.4.0
- Weakness
- CWE-1188
- Published
- 2026-04-01
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereference