Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-81100— Timescale tiger-gh-mcp-server DNS Rebinding via Disabled Host Header Allow-List

Quick assessment

Affected
timescale tiger-gh-mcp-server
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在启动 MCP HTTP 传输层时,未启用底层 SDK 提供的“主机白名单”机制。具体而言, 调用了共享的 辅助函数,但从未设置用于防护 DNS 重绑定攻击的选项。这导致该传输层接受了任意 头指定的请求,使得本地可访问的 GitHub MCP 端点可以被访客浏览器中某个指向绑定地址的页面所驱动(即存在 DNS 重绑定风险)。修复方案是显式传递该选项,并同步更新了依赖项;仅更新依赖项本身并不能完全消除该漏洞。由于该仓库尚未发布包含此修复的版本,因此受影响的范围界定为该修复提交之前的最后一个提交。

CVSS 6.8 · Medium

Possible ATT&CK Techniques 1 AI

T1189 · Drive-by Compromise

Affected Version Matrix 2

VendorProduct Version RangeStatus
timescale tiger-gh-mcp-server e559b57b57cf61277525ec96bbf1edcf01b16a21 unaffected
< e559b57b57cf61277525ec96bbf1edcf01b16a21 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81100

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Timescale tiger-gh-mcp-server DNS Rebinding via Disabled Host Header Allow-List
Source: CVE Program / CVE List V5
Vulnerability Description
tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host it named, making the locally reachable GitHub MCP endpoint drivable from a page in a visitor's browser that pointed a name it controlled at the bound address. The fix passes the option explicitly alongside a dependency update; the update alone would not have closed it. The repository has published no release that brackets the fix, so the affected boundary is the commit preceding it.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
源验证错误
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
timescale tiger-gh-mcp-server 0 ~ e559b57b57cf61277525ec96bbf1edcf01b16a21 -

II. Public POCs for CVE-2026-81100

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81100

登录查看更多情报信息。

Patches & Fixes for CVE-2026-81100 (1)

Vendor Advisories for CVE-2026-81100 (1)

Vendor Pages for CVE-2026-81100 (1)

Same Patch Batch · timescale · 2026-08-27 · 3 CVEs total

CVE-2026-81095 6.8 MEDIUM Timescale pg-aiguide through 0.5.0 DNS Rebinding via Disabled Host Header Allow-List
CVE-2026-81099 6.8 MEDIUM Timescale tiger-slack DNS Rebinding via Disabled Host Header Allow-List

IV. Related Vulnerabilities

V. Comments for CVE-2026-81100

No comments yet


Leave a comment