CVE-2026-63118 | modelcontextprotocol ruby-sdk up to 0.22.x StreamableHTTPTransport dns rebinding

SecurityVulns

A vulnerability, which was classified as critical, was found in modelcontextprotocol ruby-sdk up to 0.22.x. Affected by this vulnerability is the function MCP::Server::Transports::StreamableHTTPTransport of the component StreamableHTTPTransport. Executing a manipulation can lead to reliance on reverse dns resolution.

The identification of this vulnerability is CVE-2026-63118. The attack may be launched remotely. There is no exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More