Google's MCP Toolbox was found vulnerable to a DNS rebinding attack tracked as CVE-2026-9739, affecting deployments that use Server-Sent Events (SSE) under specification v2024-11-05. The flaw stemmed from a hardcoded permissive CORS header, Access-Control-Allow-Origin: *, left in the SSE initialization handler even after allowed-origins and allowed-hosts controls were introduced during beta. The issue is classified as CWE-942 and was reported to Google through cve-coordination@google.com, with public disclosure tied to GitHub issue #3053.
Researchers said the weakness could let an attacker abuse a victim's browser to access internal MCP Toolbox services and connected enterprise databases, potentially exposing sensitive data and enabling unauthorized queries. Google addressed the issue in pull request #3054 by removing the wildcard origin behavior and enforcing stricter origin validation. Organizations using MCP Toolbox are being urged to upgrade to the patched release, limit allowed origins to trusted domains, disable unnecessary SSE endpoints, audit internet-exposed SSE services, and watch for unusual internal request patterns that could indicate exploitation.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The issue was fixed in pull request #3054 by removing the hardcoded Access-Control-Allow-Origin wildcard and enforcing stricter origin validation. The fix addressed the retained permissive CORS behavior in the SSE initialization handler.
The vulnerability was publicly disclosed through GitHub issue #3053, describing a permissive CORS wildcard in the MCP Toolbox SSE handler that enabled DNS rebinding attacks. Reporting says the flaw particularly affected SSE deployments under specification v2024-11-05.
The CVE entry states that CVE-2026-9739 was received by cve-coordination@google.com on May 27, 2026. The vulnerability affects Google APIs MCP Toolbox and involves a DNS rebinding issue in the SSE handler.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.