SSRF Vulnerability in MCP Atlassian Server Affecting Confluence and Jira
CVE-2026-77242

7.5HIGH

Key Information:

Vendor

Sooperset

Vendor
CVE Published:
22 September 2026

What is CVE-2026-77242?

The MCP Atlassian server, utilized in conjunction with Atlassian products like Confluence and Jira, is vulnerable due to an SSRF issue where hostname resolution discrepancies can lead to unauthorized access. Specifically, prior to version 0.22.0, the function validate_url_for_ssrf fails to adequately evaluate hostname resolved addresses as Requests and urllib3 re-resolve the hostname during connection. This sequence enables an attacker to exploit short-lived DNS records, thus bypassing safeguards intended to protect internal resources and endpoints, including metadata. The vulnerability has been addressed in version 0.22.0, and users are advised to upgrade to mitigate potential risks.

Affected Version(s)

mcp-atlassian < 0.22.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.