HIGH
mark3labs
CVE published 2026-08-27
CVE-2026-81092
A vulnerability in mcp-go allows an attacker to bypass Host header validation on loopback connections, potentially enabling DNS rebinding attacks. This issue was addressed in version 0.56.0. The vulnerability affects mcp-go instances listening on loopback addresses, and defenders should assess exposure and verify version 0.56.0 or later is in use. The CVE record and NVD entry provide details on the vulner [truncated]