CVE-2026-9739
published 2026-05-27CVE-2026-9739: Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `allowed-hosts` flags to…
PriorityP348critical9.4CVSS 4.0
AVNACLATNPRNUIAVCHVIHVAHSCHSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.28%
19.9th percentile
Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `allowed-hosts` flags to align with MCP security guidelines. However, the hardcoded `Access-Control-Allow-Origin: *` header in the SSE initialization handler was inadvertently retained. This vulnerability specifically impacts users connecting via Toolbox using SSE under specification v2024-11-05.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | googleapis_mcp-toolbox | >= 0 < 1.2.0 | 1.2.0 |
| mcp_toolbox_for_databases | < PR 3054 (Fix CORS bypass) | PR 3054 (Fix CORS bypass) |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
MCP Toolbox for Databases vulnerable to DNS rebinding attacks
ghsa·2026-05-28
CVE-2026-9739 [CRITICAL] CWE-942 MCP Toolbox for Databases vulnerable to DNS rebinding attacks
MCP Toolbox for Databases vulnerable to DNS rebinding attacks
Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `allowed-hosts` flags to align with MCP security guidelines. However, the hardcoded `Access-Control-Allow-Origin: *` header in the SSE initialization handler was inadvertently retained. This vulnerability specifically impacts users connecting via Toolbox using SSE under specification v2024-11-05.
GHSA
GHSA-7pf3-8xx7-rvhf: Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790)
ghsa_unreviewed·2026-05-28
CVE-2026-9739 [CRITICAL] CWE-942 GHSA-7pf3-8xx7-rvhf: Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790)
Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `allowed-hosts` flags to align with MCP security guidelines. However, the hardcoded `Access-Control-Allow-Origin: *` header in the SSE initialization handler was inadvertently retained. This vulnerability specifically impacts users connecting via Toolbox using SSE under specification v2024-11-05.
No detection rules found.
No public exploits indexed.
2026-05-27
Published