Unauthenticated HTTP Endpoints Exposing Database MCP Server - DBHub by Bytebase
CVE-2026-61742
9.3CRITICAL
What is CVE-2026-61742?
DBHub, a database MCP server supporting multiple database types like Postgres and MySQL, has a vulnerability stemming fromunauthenticated HTTP MCP endpoints available in versions prior to 0.22.5. This issue arises when running the server in HTTP transport mode, potentially allowing attackers to exploit DNS rebinding vulnerabilities. If an attacker successfully rebinds a hostname to the DBHub HTTP server, they can manipulate the Origin and Host headers to invoke malicious MCP tool calls from the victim's browser. This exploitation could enable unauthorized access to read, enumerate, and write database contents, depending on the configurations and permissions set on DBHub. The issue was addressed in version 0.22.5.
Affected Version(s)
dbhub < 0.22.5
