Server-side Request Forgery Vulnerability in MCP Atlassian Product
CVE-2026-77274
8.8HIGH
What is CVE-2026-77274?
The MCP Atlassian server for Confluence and Jira contains a vulnerability in the validate_url_for_ssrf function that leads to authority confusion. This occurs when the function processes URL headers differently compared to the Requests connection layer. An attacker could exploit this by crafting a malicious URL that would validate as an external hostname, while the HTTP client may connect to an internal host, granting access to protected network resources. The issue has been addressed in version 0.22.0 of the product.
Affected Version(s)
mcp-atlassian < 0.22.0
