Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-61568— @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport

Quick assessment

Affected
zereight gitlab-mcp
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

是一个用于 GitLab 的 Model Context Protocol(MCP)服务器。2.1.30 版本之前的版本在 Streamable HTTP MCP 端点处未设置有效的 Host 或 Origin 白名单。恶意网页可以利用 DNS 重绑定(DNS Rebinding)技术,将浏览器的请求路由到受害者本地的 MCP 监听服务,同时保留攻击者控制的 和 头。服务器会接受这些头信息,并进入 MCP 初始化流程,而不是在 HTTP 边界处直接拒绝请求。2.1.30 版本已包含针对此问题的修复。

CVSS 9.6 · Critical

Possible ATT&CK Techniques 1 AI

T1567 · Exfiltration Over Web Service
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-61568

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport
Source: CVE Program / CVE List V5
Vulnerability Description
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route browser requests to a victim's local MCP listener while preserving an attacker-controlled `Host` and `Origin`. The server accepts those headers and reaches the MCP initialization path instead of rejecting the request at the HTTP boundary. Version 2.1.30 contains a patch.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
不恰当地信任反向DNS
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
zereight gitlab-mcp < 2.1.30 -

II. Public POCs for CVE-2026-61568

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-61568

登录查看更多情报信息。

Patches & Fixes for CVE-2026-61568 (2)

Vendor Advisories for CVE-2026-61568 (1)

Vendor Pages for CVE-2026-61568 (1)

Same Patch Batch · zereight · 2026-09-15 · 3 CVEs total

CVE-2026-61560 9.8 CRITICAL @zereight/mcp-gitlab's unauthenticated arbitrary file read via `upload_markdown` enables P
CVE-2026-61559 9.6 CRITICAL @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery

IV. Related Vulnerabilities

V. Comments for CVE-2026-61568

No comments yet


Leave a comment