Server Misconfiguration in mcp-go Affects Loopback Connections
CVE-2026-81092
7.6HIGH
What is CVE-2026-81092?
The mcp-go server software fails to verify the Host header for requests arriving over its HTTP transports. This oversight allows potentially dangerous requests from a controlled browser page that point to the loopback address to access server resources as if they were local. Prior to version 0.56.0, both the StreamableHTTPServer and SSEServer did not validate incoming requests, leading to possible exploitation through techniques like DNS rebinding. Version 0.56.0 introduces crucial Host header validation that mitigates this risk by rejecting inappropriate loopback requests.
Affected Version(s)
mcp-go 0 < 0.56.0
