THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-9g45-5xwm-f3wc (medium) — RMCP: Custom HTTP headers leak to cross-origin redirect targets

[GHSA] GHSA-9g45-5xwm-f3wc (medium) — RMCP: Custom HTTP headers leak to cross-origin redirect targets

highgithub_advisoriesPublished 2026-09-17

GHSA-9g45-5xwm-f3wc Severity: medium CVE: CVE-2026-64684

RMCP: Custom HTTP headers leak to cross-origin redirect targets

## Summary

The `rmcp` crate's `StreamableHttpClientTransport` forwards caller-supplied custom HTTP headers (such as `X-API-Key`, `X-Auth-Token`, `Api-Key`) to cross-origin redirect targets. The `default_http_client()` function builds a `reqwest::Client` without a redirect pol

Indicators of compromise

Original source: https://github.com/advisories/GHSA-9g45-5xwm-f3wc