PatchSiren

mark3labs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH mark3labs CVE published 2026-08-27

CVE-2026-81092

A vulnerability in mcp-go allows an attacker to bypass Host header validation on loopback connections, potentially enabling DNS rebinding attacks. This issue was addressed in version 0.56.0. The vulnerability affects mcp-go instances listening on loopback addresses, and defenders should assess exposure and verify version 0.56.0 or later is in use. The CVE record and NVD entry provide details on the vulner [truncated]