Server-side Request Forgery Vulnerability in MCP Atlassian Product
CVE-2026-77274

8.8HIGH

Key Information:

Vendor

Sooperset

Vendor
CVE Published:
22 September 2026

What is CVE-2026-77274?

The MCP Atlassian server for Confluence and Jira contains a vulnerability in the validate_url_for_ssrf function that leads to authority confusion. This occurs when the function processes URL headers differently compared to the Requests connection layer. An attacker could exploit this by crafting a malicious URL that would validate as an external hostname, while the HTTP client may connect to an internal host, granting access to protected network resources. The issue has been addressed in version 0.22.0 of the product.

Affected Version(s)

mcp-atlassian < 0.22.0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.