CRITICAL 10.0 GitHub

CVE-2026-59971

MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)

## Summary In SSE/HTTP transport mode, `mysql_mcp_server` constructs `SseServerTransport` without passing `security_settings`. As a result, the MCP Python SDK's DNS-rebinding protection (Origin/Host header validation) is disabled; the Starlette application has no CORS or TrustedHost middleware; and the service binds to `0.0.0.0` by default with no authentication on any route. **Trigger condition:** `MCP_TRANSPORT=sse`. The default stdio mode is not affected. ## Attack Scenarios **Scenario A

Affected Products

References

Published: 2026-09-11 · Source: GitHub · Feed updated: 2026-09-11
This critical severity vulnerability with a CVSS score of 10.0 was published on 2026-09-11 via GitHub. Affected: pip/mysql-mcp-server < 0.4.2.

Risk Timeline

CVE Disclosed2026-09-11 · -1 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2026-78676GitPython: Dormant multi-line git-config values are corrupted into live injectedCRITICAL9.8
CVE-2026-59151Prowler: SAML Domain Claiming Enables Cross-Tenant Account TakeoverCRITICAL9.6
CVE-2026-79657NLTK: Allowlisted pickle loaders still permit code execution in current sourceCRITICAL
CVE-2026-78683NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code ExecuCRITICAL
CVE-2026-59177ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA adHIGH8.8
CVE-2026-78675GitPython: Arbitrary local file content disclosure via [include] directive in unHIGH8.4
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.