CVE-2026-55837 | dbt-labs dbt-mcp up to 1.19.x OAuth Helper fastapi_app.py dns rebinding
A vulnerability described as critical has been identified in dbt-labs dbt-mcp up to 1.19.x. The affected element is an unknown function of the file src/dbt_mcp/oauth/fastapi_app.py of the component OAuth Helper. Executing a manipulation can lead to reliance on reverse dns resolution.
This vulnerability appears as CVE-2026-55837. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More