
Cloud Vulnerability DB
A community-led vulnerabilities database
The rmcp OAuth client accepts a server-controlled resource_metadata= URL from the WWW-Authenticate header and fetches it without same-origin or private-network validation.
An attacker-controlled MCP server can return a 401 WWW-Authenticate: Bearer resource_metadata="..." header pointing at an internal URL, including localhost, RFC 1918 addresses, or cloud metadata endpoints. The client then performs an outbound GET to that URL from the victim application's network context.
modelcontextprotocol/rust-sdkrmcpmain reviewed: c330fede90e4729c234f8e87fdbc5ea27a1dd10ccrates/rmcp/src/transport/auth.rs3aa3e91310662c409af9dc38c9d584d6df217e9cextract_www_authenticate_params() accepts an absolute URL from the server-controlled header:
let resource_key = "resource_metadata=";
while let Some(pos) = header_lowercase[search_offset..].find(resource_key) {
let global_pos = search_offset + pos + resource_key.len();
let value_slice = &header[global_pos..];
if let Some((value, consumed)) = Self::parse_next_header_value(value_slice) {
if let Ok(url) = Url::parse(&value) {
params.resource_metadata_url = Some(url);
break;
}
if let Ok(url) = base_url.join(&value) {
params.resource_metadata_url = Some(url);
break;
}There is no check that the parsed URL shares origin with the original MCP server, and no block for loopback, link-local, RFC 1918, or metadata hostnames.
fetch_resource_metadata_from_url() then performs the GET:
let response = match self
.http_client
.get(resource_metadata_url.clone())
.header(HEADER_MCP_PROTOCOL_VERSION, "2024-11-05")
.send()
.awaitAgain, there is no same-origin, scheme, host, DNS, or IP-range validation before the request.
rmcp connects to an attacker-controlled MCP server, or to a compromised MCP server.401 and a WWW-Authenticate header such as:WWW-Authenticate: Bearer resource_metadata="http://169.254.169.254/latest/meta-data/"resource_metadata value as a URL.The direct impact is SSRF from any application embedding the rmcp OAuth client. Depending on where the client runs, this can reach:
WWW-Authenticate header.On 2026-05-27:
GHSA-9g45-5xwm-f3wc: custom HTTP headers leak to cross-origin redirect targets.GHSA-89vp-x53w-74fx: DNS rebinding in Streamable HTTP server transport.WWW-Authenticate resource_metadata SSRF returned no open or closed matches.resource_metadata returned one closed implementation issue, #517, about authorization discovery fallback behavior, not SSRF/resource validation.
This report is distinct from the redirect-header advisory and the DNS-rebinding advisory.Before accepting or fetching a resource_metadata URL:
fn is_same_origin(base: &Url, candidate: &Url) -> bool {
base.scheme() == candidate.scheme()
&& base.host() == candidate.host()
&& base.port_or_known_default() == candidate.port_or_known_default()
}If cross-origin resource_metadata is required for compatibility, it should be explicitly opted into and protected by private-network blocking.
Source: NVD
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."