CVE-2026-77267 | sooperset mcp-atlassian up to 0.21.x Authentication Header Processing _process_authentication_headers X-Atlassian-Jira-Url/X-Atlassian-Confluence-Url server-side request forgery

SecurityVulns

A vulnerability, which was classified as critical, has been found in sooperset mcp-atlassian up to 0.21.x. This issue affects the function _process_authentication_headers of the component Authentication Header Processing. This manipulation of the argument X-Atlassian-Jira-Url/X-Atlassian-Confluence-Url causes server-side request forgery.

This vulnerability is tracked as CVE-2026-77267. The attack is possible to be carried out remotely. No exploit exists.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More