THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-81100 (MEDIUM 6.8) — tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host i

[NVD] CVE-2026-81100 (MEDIUM 6.8) — tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host i

mednvdPublished 2026-08-27

CVE-2026-81100 CVSS: 6.8 MEDIUM Published: 2026-08-27T17:20:52.620

tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host it named, making the locally reachable GitHub MCP end

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81100