What is CVE-2026-16328?
CVE-2026-16328 is a vulnerability in consul-mcp-server versions 0.1.0 through 0.1.3 that allows a connected client to override the server's Consul backend address via a request header, potentially enabling malicious clients to redirect the server's Consul API traffic to an attacker-controlled destination. It is recommended to upgrade to a version above 0.1.3 immediately.
Azərbaycanca: CVE-2026-16328, consul-mcp-server-in 0.1.0-dan 0.1.3-ə qədər versiyalarında aşkarlanan boşluqdur: qoşulmuş müştəri sorğu başlığı (request header) vasitəsilə serverin Consul backend ünvanını dəyişə bilər, bu da zərərli şəxslərə serverin API trafikini öz idarə etdikləri hədəfə yönləndirməyə imkan yarada bilər. Təhlükəni dərhal minimuma endirmək üçün serveri 0.1.3-dən yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
Which versions of consul-mcp-server are affected by CVE-2026-16328?
This vulnerability affects consul-mcp-server versions 0.1.0 through 0.1.3.
How can CVE-2026-16328 be mitigated?
It is recommended to immediately upgrade to a version above 0.1.3.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.