CVE-2026-42559: DNS Rebinding in rmcp's Streamable HTTP Server Transport
This story is from 2026-09-20. It is preserved in the archive; the latest stories are on the live feed.
Overview Field Value CVE ID CVE-2026-42559 Component rmcp (official Rust SDK for the Model Context Protocol) Vulnerable location crates/rmcp/src/transport/streamable_http_server/tower.rs Affected versions rmcp Patched version rmcp >= 1.4.0 (commit 8e22aa2 , PR #764) CVSS 3.1 8.8 (High) — AV:N/AC:L/…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-20 06:48 · DEV Community — AI
CVE-2026-42559: DNS Rebinding in rmcp's Streamable HTTP Server Transport