{"id":"CVE-2026-63118","aliases":["GHSA-rjr6-rcgv-9m7m"],"url":"https://o3.security/vulnerability/CVE-2026-63118","summary":"MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection","details":"MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not validate the HTTP Host or Origin request headers, which allows a malicious browser page to use DNS rebinding to reach a locally running MCP server and invoke exposed tools. This issue is fixed in version 0.23.0.","published":"2026-07-29T19:07:33.452Z","modified":"2026-08-12T03:51:34.998472600Z","cvss":null,"epss":{"score":0.00195,"percentile":0.09394,"asOf":"2026-09-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"mcp","fixedVersion":"0.23.0"}],"fix":{"url":"https://github.com/modelcontextprotocol/ruby-sdk/commit/ba543083a7594e7892b29464b89091816446ff7a","label":"modelcontextprotocol/ruby-sdk@ba54308"},"references":[{"type":"WEB","url":"https://github.com/modelcontextprotocol/ruby-sdk/releases/tag/v0.23.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63118.json"},{"type":"ADVISORY","url":"https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-rjr6-rcgv-9m7m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63118"},{"type":"FIX","url":"https://github.com/modelcontextprotocol/ruby-sdk/commit/ba543083a7594e7892b29464b89091816446ff7a"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:34.998472600Z"}}