CVE-2026-42559 affects the official Rust Model Context Protocol SDK (rmcp) prior to version 1.4.0. The vulnerability is in the Streamable HTTP server transport under crates/rmcp/src/transport/streamable_http_server/, which did not validate the incoming HTTP Host header. Because of this missing validation, a malicious public website could exploit DNS rebinding to cause a victim’s browser to send authenticated requests to an MCP server bound to the victim’s loopback or private-network interface. The issue is specific to the HTTP server transport; non-HTTP transports such as stdio and child-process transports are not affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This is a self-contained Docker laboratory and functional Python proof of concept for CVE-2026-42559, an rmcp Streamable HTTP transport Host-header/origin-validation flaw affecting versions before 1.4.0. The repository contains a Python exploit, Docker Compose orchestration, and a Rust MCP server built twice from identical source: rmcp 1.3.0 is exposed through localhost port 8000 as the vulnerable instance, while rmcp 1.4.0 is exposed through port 8001 as the patched comparison instance. The Python client directly connects to a supplied IP:port but uses http.client.putrequest(..., skip_host=True) to emit a forged Host header and a corresponding Origin, reproducing the HTTP request produced after browser DNS rebinding without operating DNS infrastructure. After a successful forged initialize request, it preserves the returned Mcp-Session-Id, sends notifications/initialized, enumerates MCP tools, and invokes whoami, read_file, and run_command. The Rust lab server intentionally implements arbitrary-path file reading and `sh -c` command execution, while Docker seeds fake credentials and key material for demonstration. Patched behavior is recognized by HTTP 403 on the forged Host; the exploit therefore serves as both an exploit demonstrator and a version/mitigation validation check, but performs active post-compromise actions against vulnerable targets.
This seven-file standalone Docker lab demonstrates CVE-2026-42559 in rmcp's Streamable HTTP server transport before version 1.4.0. The primary exploit entry point, exploit/exploit.py, is dependency-free Python 3.9+ code that opens a direct TCP HTTP connection and deliberately suppresses the standard Host header before supplying an attacker-controlled Host and Origin. This reproduces the HTTP request produced after a DNS-rebinding attack without implementing DNS infrastructure. It uses MCP JSON-RPC to initialize a session, distinguish patched targets by their 403 response, enumerate exposed tools, and invoke them. The Rust MCP server in mcp-server/src/main.rs intentionally exposes powerful developer-assistant tools: whoami, arbitrary text-file reads, and `sh -c` command execution. Docker builds identical server source against rmcp 1.3.0 (vulnerable) and 1.4.0 (patched), publishing them on loopback ports 8000 and 8001 respectively. The image seeds only fake credentials and a fake SSH key for safe demonstration. The vulnerability is in the rmcp transport's absent Host allowlist, not in the Rust application code; however, exploitation impact is determined by whatever MCP tools the target server exposes. The repository also includes the compose orchestration, Cargo dependency manifest, and Docker build recipe.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Host header validation flaw in the RMCP Rust SDK Streamable HTTP server transport that enables DNS rebinding attacks against MCP servers on loopback or private-network interfaces.
A DNS rebinding vulnerability in the rmcp crate's Streamable HTTP server transport caused by missing Host header validation, allowing a malicious website to access and interact with a locally running or private-network-exposed rmcp-based MCP server.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.