7.5
CVE-2026-77265
- EPSS 0.26%
- Veröffentlicht 22.09.2026 17:47:58
- Zuletzt bearbeitet 29.09.2026 19:00:07
- Erkennungen
MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, header-supplied Jira or Confluence URLs are resolved and validated before the HTTP client resolves the hostname again for the connection. An unauthenticated caller can use a DNS-rebinding hostname that returns a public address during validation and an internal address during connection, causing requests to internal or metadata services. The advisory traces the vulnerable input and processing flow through X-Atlassian-Jira-Url, X-Atlassian-Confluence-Url, validate_url_for_ssrf, and DNS rebinding, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mcp-atlassian ≫ Mcp Atlassian Version < 0.22.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.159 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| security-advisories@github.com | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
https://github.com/sooperset/mcp-atlassian/pull/1448
https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460
https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0
https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-49xv-9743-pw8w