Skip to content
mcp-toolboxGHSA-7pf3-8xx7-rvhf

MCP Toolbox for Databases vulnerable to DNS rebinding attacks

CriticalCVE-2026-9739 · Published May 28, 2026 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/googleapis/mcp-toolbox
Go
< 1.2.01.2.0
Details and references

Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `allowed-hosts` flags to align with MCP security guidelines. However, the hardcoded `Access-Control-Allow-Origin: *` header in the SSE initialization handler was inadvertently retained. This vulnerability specifically impacts users connecting via Toolbox using SSE under specification v2024-11-05.

CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-942
Also known as
CVE-2026-9739, GO-2026-5870

More mcp-toolbox advisories

All
DateAdvisory
Jun 13MCP Toolbox for Databases has an Origin Validation Error
CVE-2026-11624Criticalfixed in 0.25.0
Jun 18googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken)
CVE-2026-11717Criticalfixed in 1.4.0
Jun 18googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken)
CVE-2026-11718Criticalfixed in 1.4.0
Jun 18MCP Toolbox for Databases: authenticated authorization bypass
CVE-2026-11719Highfixed in 1.4.0
Jun 29MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints
CVE-2026-11720Critical9.1fixed in 1.3.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.