THREAT OPS › Threat News › [NVD] CVE-2026-81100 (MEDIUM 6.8) — tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host i
[NVD] CVE-2026-81100 (MEDIUM 6.8) — tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host i
CVE-2026-81100 CVSS: 6.8 MEDIUM Published: 2026-08-27T17:20:52.620
tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host it named, making the locally reachable GitHub MCP end
Indicators of compromise
- CVE-2026-81100cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81100