tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host it named, making the locally reachable GitHub MCP endpoint drivable from a page in a visitor's browser that pointed a name it controlled at the bound address. The fix passes the option explicitly alongside a dependency update; the update alone would not have closed it. The repository has published no release that brackets the fix, so the affected boundary is the commit preceding it.
Metrics
Affected Vendors & Products
References
History
Sat, 29 Aug 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Timescale
Timescale tiger-gh-mcp-server |
|
| Vendors & Products |
Timescale
Timescale tiger-gh-mcp-server |
Thu, 27 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host it named, making the locally reachable GitHub MCP endpoint drivable from a page in a visitor's browser that pointed a name it controlled at the bound address. The fix passes the option explicitly alongside a dependency update; the update alone would not have closed it. The repository has published no release that brackets the fix, so the affected boundary is the commit preceding it. | |
| Title | Timescale tiger-gh-mcp-server DNS Rebinding via Disabled Host Header Allow-List | |
| Weaknesses | CWE-346 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-08-27T14:50:39.728Z
Updated: 2026-08-29T11:48:13.548Z
Reserved: 2026-08-26T16:00:33.768Z
Link: CVE-2026-81100
Updated: 2026-08-29T03:01:18.937Z
Status : Received
Published: 2026-08-27T17:20:52.620
Modified: 2026-08-29T04:18:07.003
Link: CVE-2026-81100
No data.