SSRF Vulnerability in MCP Atlassian Server Affecting Confluence and Jira
CVE-2026-77242
7.5HIGH
What is CVE-2026-77242?
The MCP Atlassian server, utilized in conjunction with Atlassian products like Confluence and Jira, is vulnerable due to an SSRF issue where hostname resolution discrepancies can lead to unauthorized access. Specifically, prior to version 0.22.0, the function validate_url_for_ssrf fails to adequately evaluate hostname resolved addresses as Requests and urllib3 re-resolve the hostname during connection. This sequence enables an attacker to exploit short-lived DNS records, thus bypassing safeguards intended to protect internal resources and endpoints, including metadata. The vulnerability has been addressed in version 0.22.0, and users are advised to upgrade to mitigate potential risks.
Affected Version(s)
mcp-atlassian < 0.22.0
