CVE-2026-42559
high
CVSS v3
8.8
CVSS v2
—
VIR risk
8.8
Description
rmcp Streamable HTTP server transport has a DNS rebinding vulnerability
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| crates.io | dynoxide-rs | | |
| crates.io | dynoxide-rs | >=0.9.3,<0.9.13 | 0.9.13 |
| npm | dynoxide | >=0.9.3,<0.9.13 | 0.9.13 |
| crates.io | rmcp | <1.4.0 | 1.4.0 |
| RUST | rmcp | < 1.4.0 | 1.4.0 |
References
- https://github.com/nubo-db/dynoxide/security/advisories/GHSA-fvh2-gm75-j4j7
- https://github.com/modelcontextprotocol/rust-sdk/commit/8e22aa2de28df5a285eed87c11cd89bf15fa90d3
- https://github.com/modelcontextprotocol/rust-sdk/issues/815
- https://github.com/modelcontextprotocol/rust-sdk/issues/822
- https://github.com/modelcontextprotocol/rust-sdk/pull/764
- https://github.com/modelcontextprotocol/rust-sdk/security/advisories/GHSA-89vp-x53w-74fx
- https://github.com/nubo-db/dynoxide
- https://github.com/nubo-db/dynoxide/releases/tag/v0.9.13
- https://rustsec.org/advisories/RUSTSEC-2026-0140.html
- https://nvd.nist.gov/vuln/detail/CVE-2026-42559
- https://github.com/modelcontextprotocol/rust-sdk
- https://modelcontextprotocol.io/specification/2025-06-18/basic/transports#security-warning
- https://crates.io/crates/dynoxide-rs
- https://github.com/advisories/GHSA-89vp-x53w-74fx
CWEs
CWE-346 CWE-350
Verify integrity in audit chain (admin only). AS-IS.