PatchSiren cyber security CVE debrief
CVE-2026-77265 sooperset CVE debrief
An unauthenticated caller can use a DNS-rebinding hostname that returns a public address during validation and an internal address during connection, causing requests to internal or metadata services in MCP Atlassian prior to 0.22.0. This issue allows for potential unauthorized access and requires defenders to assess exposure and prioritize upgrading to version 0.22.0 or later. The vulnerability is triggered through header-supplied Jira or Confluence URLs, which are resolved and validated before the HTTP client resolves the hostname again for the connection.
- Vendor
- sooperset
- Product
- mcp-atlassian
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-22
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-22
- Advisory updated
- 2026-09-28
Who should care
Defenders of MCP Atlassian instances, especially those with internet-facing access, should assess exposure and prioritize upgrading to version 0.22.0 or later. This includes reviewing instance configurations, monitoring for suspicious activity, and implementing compensating controls to restrict access to internal services. Additionally, defenders should review relevant monitoring, detection, and logs for exposed assets that need extra review.
Why it matters
This vulnerability allows an unauthenticated caller to use a DNS-rebinding hostname, potentially leading to unauthorized access to internal or metadata services. Defenders should prioritize verifying exposure of MCP Atlassian instances and upgrading to version 0.22.0 or later.
- Potential unauthorized access to internal or metadata services
- Possible bypass of security controls
- Requires verification of instance exposure and upgrade to fixed version
Technical summary
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, header-supplied Jira or Confluence URLs are resolved and validated before the HTTP client resolves the hostname again for the connection. This allows an unauthenticated caller to use a DNS-rebinding hostname that returns a public address during validation and an internal address during connection, causing requests to internal or metadata services. The vulnerability is fixed in version 0.22.0, and defenders should prioritize verifying exposure of MCP Atlassian instances and upgrading to the fixed version.
Defensive priority
Defenders should prioritize verifying exposure of MCP Atlassian instances, especially those with internet-facing access, and upgrade to version 0.22.0 or later.
Recommended defensive actions
- Verify MCP Atlassian instance exposure and upgrade to version 0.22.0 or later
- Monitor for suspicious requests to internal or metadata services
- Implement compensating controls to restrict access to internal services
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
Evidence notes
The advisory traces the vulnerable input and processing flow through X-Atlassian-Jira-Url, X-Atlassian-Confluence-Url, validate_url_for_ssrf, and DNS rebinding, which identify the affected entry points, controls, and code paths. This information is crucial for defenders to understand the vulnerability and implement necessary mitigations. The advisory provides a detailed analysis of the vulnerability, including the affected components and potential impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-77265 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-77265
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-77265 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77265
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/pull/1448
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-49xv-9743-pw8w
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.