What is CVE-2026-63118?
The MCP Ruby SDK, specifically the mcp gem's StreamableHTTPTransport component, fails to validate HTTP Host or Origin headers. This vulnerability allows a malicious browser page to perform a DNS rebinding attack to access a local MCP server. Versions prior to 0.23.0 are affected and should be updated immediately.
Azərbaycanca: MCP Ruby SDK-da (Model Context Protocol üçün rəsmi Ruby SDK) mcp gem-in StreamableHTTPTransport komponenti HTTP Host və Origin başlıqlarını yoxlamır. Bu zəiflik DNS rebinding hücumları vasitəsilə zərərli brauzer səhifəsinin lokal serverə çıxış əldə etməsinə imkan verir. 0.23.0 versiyasından əvvəlki versiyalar təsirlənir və dərhal yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which component in the MCP Ruby SDK is affected by CVE-2026-63118?
The vulnerability affects the StreamableHTTPTransport component of the mcp gem, as it fails to validate HTTP Host or Origin headers.
Which version should be updated to in order to mitigate CVE-2026-63118?
Affected versions are those prior to 0.23.0, so an immediate update is required.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.