Skip to content
archivevulnerability · 11 Sep 2026 · 20:35 UTC

GHSA-rqfv-2mw9-78g2: MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS R

VULNCVE-2026-59971source · GTH
HIGHCritical vulnerability — CVSS 10
What to do
  • Critical severity — schedule an urgent patch.

last 60 dispatches · spectrum

## Summary In SSE/HTTP transport mode, `mysql_mcp_server` constructs `SseServerTransport` without passing `security_settings`. As a result, the MCP Python SDK's DNS-rebinding protection (Origin/Host header validation) is disabled; the Starlette application has no CORS or TrustedHost middleware; and the service binds to `0.0.0.0` by default with no authentication on any route. **Trigger condition:** `MCP_TRANSPORT=sse`. The default stdio mode is not affected. …

CVE · detail
grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected