THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-vmp7-252j-cwp7 (critical) — @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport

[GHSA] GHSA-vmp7-252j-cwp7 (critical) — @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport

highgithub_advisoriesPublished 2026-09-15

GHSA-vmp7-252j-cwp7 Severity: critical CVE: CVE-2026-61568

@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport

`@zereight/mcp-gitlab` exposes its Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route browser requests to a victim's local MCP listener while preserving an attacker-controlled `Host`

Indicators of compromise

Original source: https://github.com/advisories/GHSA-vmp7-252j-cwp7