What is CVE-2026-49857?
A critical SSRF vulnerability exists in the auth-fetch-mcp server where the `isPrivateV6()` function in version 3.0.1 fails to detect IPv4-mapped IPv6 addresses, allowing access to private and loopback addresses. Immediate update to the latest version is recommended to mitigate the risk.
Azərbaycanca: auth-fetch-mcp serverində kritik SSRF zəifliyi aşkarlanıb. Versiya 3.0.1-də `isPrivateV6()` funksiyası IPv4-mapped IPv6 ünvanlarını düzgün aşkarlamır və yerli şəbəkəyə giriş bloklanmır. Təcili olaraq serveri ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
What is the cause of CVE-2026-49857 in the auth-fetch-mcp server?
In version 3.0.1, the `isPrivateV6()` function incorrectly detects IPv4-mapped IPv6 addresses, failing to block access to private networks and loopback addresses.
What is the recommended mitigation for the CVE-2026-49857 SSRF vulnerability?
To mitigate this risk, the auth-fetch-mcp server should be immediately updated to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.