System running
Last check: 2026-09-29 03:27:30 | Auto-updates every hour
756 PoCs
CybersecPlayground | The ultimate platform for cybersecurity learning & Bug Bounty Resources

CVE-CVE-2026-42559

Severity
HIGH
CVSS Score
8.8
Description

RMCP is an official Rust SDK for the Model Context Protocol. Prior to version 1.4.0, the rmcp crate's Streamable HTTP server transport (crates/rmcp/src/transport/streamable_http_server/) did not validate the incoming Host header. This allowed a malicious public website, via a DNS rebinding attack, to send authenticated requests to an MCP server running on the victim's loopback or private-network interface. This vulnerability is fixed in 1.4.0....

PoCs for CVE-CVE-2026-42559

CVE-2026-42559
General Python 0
joaovicdev 2026-09-06
Master Cybersecurity | Join CybersecPlayground for Cybersecurity Learning & Bug Bounty Resources