CVE-2026-55837 | dbt-labs dbt-mcp up to 1.19.x OAuth Helper fastapi_app.py dns rebinding

SecurityVulns

A vulnerability described as critical has been identified in dbt-labs dbt-mcp up to 1.19.x. The affected element is an unknown function of the file src/dbt_mcp/oauth/fastapi_app.py of the component OAuth Helper. Executing a manipulation can lead to reliance on reverse dns resolution.

This vulnerability appears as CVE-2026-55837. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More