CVE-2026-42559 - Vulnerability Analysis
HighCVSS: 8.8Last Updated: May 14, 2026
RMCP rmcp - DNS Rebinding
Overview
RMCP rmcp crate < 1.4.0 contains a DNS rebinding vulnerability caused by lack of validation of the incoming Host header in Streamable HTTP server transport, letting malicious websites send authenticated requests to MCP servers on victim's loopback or private network, exploit requires victim to visit malicious website.
Severity & Score
Impact
Malicious websites can send authenticated requests to local MCP servers, potentially leading to unauthorized actions on private network services.
Mitigation
Update to version 1.4.0 or later.
References
- https://github.com/modelcontextprotocol/rust-sdk/commit/8e22aa2de28df5a285eed87c11cd89bf15fa90d3
- https://github.com/modelcontextprotocol/rust-sdk/issues/815
- https://github.com/modelcontextprotocol/rust-sdk/issues/822
- https://github.com/modelcontextprotocol/rust-sdk/pull/764
- https://github.com/modelcontextprotocol/rust-sdk/security/advisories/GHSA-89vp-x53w-74fx
Social Media Activity(2 posts)
š CVE-2026-42559 - High (8.8) RMCP is an official Rust SDK for the Model Context Protocol. Prior to version 1.4.0, the rmcp crate's Streamable HTTP server transport (crates/rmcp/src/transport/streamable_http_server/) did not validate the incoming Host header. This allowed a ma... š https://www.thehackerwire.com/vulnerability/CVE-2026-42559/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš CVE-2026-42559 - High (8.8) RMCP is an official Rust SDK for the Model Context Protocol. Prior to version 1.4.0, the rmcp crate's Streamable HTTP server transport (crates/rmcp/src/transport/streamable_http_server/) did not validate the incoming Host header. This allowed a ma... š https://www.thehackerwire.com/vulnerability/CVE-2026-42559/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-42559
- Severity
- High
- CVSS Score
- 8.8
- Type
- dns_rebinding
- Status
- rejected
- EPSS
- 0.0%
- Social Posts
- 2
CWE
- CWE-346
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H