Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-55096— SSRF via DNS-resolution gap in _validate_url_security (file download by URL)

Quick assessment

Affected
leshchenko1979 fast-mcp-telegram
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

fast-mcp-telegram 是一个 Telegram MCP 服务器。在 30.1 版本之前, / MCP 工具接受由 http(s) URL 组成的文件列表,服务器会下载这些 URL 指定的文件,并将其作为附件附加到发往 Telegram 的消息中。 下载过程受 函数保护,该函数通过一个针对 SSRF(服务器端请求伪造)的拒绝列表进行校验,但它仅检查 URL 中主机名字符串的字面形式,而从不进行 DNS 解析。实际的 HTTP 请求(通过 发起)会在请求时自行完成 DNS 解析。因此,一个解析结果为环回地

CVSS 7.1 · High

Possible ATT&CK Techniques 1 AI

T1071.003 · Mail Protocols

Affected Version Matrix 1

VendorProduct Version RangeStatus
leshchenko1979 fast-mcp-telegram < 30.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-55096

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SSRF via DNS-resolution gap in _validate_url_security (file download by URL)
Source: CVE Program / CVE List V5
Vulnerability Description
fast-mcp-telegram is a Telegram MCP Server. Prior to version 30.1, the send_message/send_message_to_phone MCP tools accept files as a list of http(s) URLs, which the server downloads and attaches to the outgoing Telegram message. Downloads are guarded by _validate_url_security, an SSRF denylist that checks the URL's literal hostname string but never resolves DNS. The fetch (httpx.AsyncClient.get) does its own resolution at request time. Consequently a hostname that resolves to a loopback / private / link-local address passes the guard and is fetched — even with the secure defaults block_private_ips=True and allow_http_urls=False. Because the fetched body is returned to the attacker as a Telegram file attachment, this is a full-read, exfiltrating SSRF, not blind. This issue has been patched in version 30.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
不完整的黑名单
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
leshchenko1979 fast-mcp-telegram < 30.1 -

II. Public POCs for CVE-2026-55096

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-55096

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-55096 (2)

Vendor Advisories for CVE-2026-55096 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-55096

No comments yet


Leave a comment