All 3 CVE vulnerabilities found in toolhive, with AI-generated Chinese analysis, references, and POCs.
Vendor: stacklok
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-58196 | ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation) CWE-918 | 4.7 | Medium | 2026-09-15 |
| CVE-2026-54450 | ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway CWE-918 | 2.9 | Low | 2026-09-15 |
| CVE-2025-47274 | ToolHive stores secrets in the state store with no encryption CWE-311 | 6.5AI | Medium AI | 2025-05-12 |
All 3 known CVE vulnerabilities affecting toolhive with full Chinese analysis, references, and POCs where available.