Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-61742— DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution

Quick assessment

Affected
bytebase dbhub
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

DBHub 是一个支持 PostgreSQL、MySQL、SQL Server、Oracle、MariaDB 和 SQLite 的数据库 MCP(Model Context Protocol)服务器。在 0.22.5 之前的版本中,当使用文档中描述的 HTTP 传输模式启动时(例如执行 ),会暴露出一个未经验证身份认证的 HTTP MCP 端点。 该 HTTP 服务器试图通过检查 HTTP 请求头中的 (来源)主机名是否与 (目标)主机名相等,来防范来自浏览器的跨域访问,并将验证后的 值直接回写到 响应头中。然而,

CVSS 9.3 · Critical EPSS 0.20% · P9
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-61742

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution
Source: CVE Program / CVE List V5
Vulnerability Description
DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Versions prior to 0.22.5 expose an unauthenticated HTTP MCP endpoint when started with the documented HTTP transport mode, for example `--transport http --port 8080`. The HTTP server attempts to protect browser-origin access by checking whether the `Origin` hostname equals the `Host` hostname, then reflecting the validated `Origin` into `Access-Control-Allow-Origin`. This does not stop DNS rebinding. After an attacker-controlled hostname rebinds to a victim-accessible DBHub HTTP server, both `Origin` and `Host` can contain the attacker-controlled hostname, so DBHub accepts the request and dispatches MCP tool calls. As a result, a malicious website can deterministically invoke DBHub MCP tools from the victim's browser without prompt injection or model involvement. With the default demo configuration this can read and write the demo SQLite database; with a real configured database, the same primitive can read, enumerate, and potentially write database contents depending on DBHub's configured tool permissions and database credentials. Version 0.22.5 fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
bytebase dbhub < 0.22.5 -

II. Public POCs for CVE-2026-61742

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-61742

请登录查看更多情报信息。

Other References for CVE-2026-61742 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-61742

No comments yet


Leave a comment