GHSA-rqfv-2mw9-78g2: MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS R
HIGHCritical vulnerability — CVSS 10
What to do
- Critical severity — schedule an urgent patch.
## Summary In SSE/HTTP transport mode, `mysql_mcp_server` constructs `SseServerTransport` without passing `security_settings`. As a result, the MCP Python SDK's DNS-rebinding protection (Origin/Host header validation) is disabled; the Starlette application has no CORS or TrustedHost middleware; and the service binds to `0.0.0.0` by default with no authentication on any route. **Trigger condition:** `MCP_TRANSPORT=sse`. The default stdio mode is not affected. …
CVE · detail
- CVE-2026-59971nvd ↗EPSS 0.39%
Early access
Get the next one first.
Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.
bot-protected