THREAT OPS › Threat News › [GHSA] GHSA-rjr6-rcgv-9m7m (medium) — MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
[GHSA] GHSA-rjr6-rcgv-9m7m (medium) — MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
GHSA-rjr6-rcgv-9m7m Severity: medium CVE: CVE-2026-63118
MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
## Summary
`MCP::Server::Transports::StreamableHTTPTransport` (the Rack-mountable Streamable HTTP transport in the `mcp` gem) processes every incoming JSON-RPC request without ever inspecting the HTTP `Host` or `Origin` request headers. There is no `Allow
Indicators of compromise
- CVE-2026-63118cve
- http://evil.attacker.com`url
- http://evil.attacker.comurl
- http://127.0.0.1:8080url
- attacker.evil.comdomain
Original source: https://github.com/advisories/GHSA-rjr6-rcgv-9m7m