{"id":"CVE-2026-54450","title":"ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers","summary":"ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.29.1, networking.IsPrivateIP in pkg/networking/utilities.go omits the IPv6 NAT64 prefixes 64:ff9b::/96 and 64:ff…","severity":"low","cvss":2.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P","cwe":["CWE-918"],"vendor":"stacklok","product":"toolhive","affected":["toolhive < 0.29.1"],"patched":["github.com/stacklok/toolhive 0.29.1"],"published":"2026-09-15","updated":"2026-09-15","sourceUpdated":"2026-09-15T17:17:20.480","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-54450","references":[{"url":"https://github.com/stacklok/toolhive/commit/26912af453d2040787983dbc9ab93a9019ec0468","label":"security-advisories@github.com"},{"url":"https://github.com/stacklok/toolhive/releases/tag/v0.29.1","label":"security-advisories@github.com"},{"url":"https://github.com/stacklok/toolhive/security/advisories/GHSA-pph6-vfjv-vpjw","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-pph6-vfjv-vpjw"}],"tags":["nvd","cve.org","ghsa","go"],"aliases":["GHSA-pph6-vfjv-vpjw"],"ecosystem":"go","ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-15T16:12:58.689222Z"},"cvssSource":"cna","ingestedAt":"2026-07-15T22:46:58.967Z","epss":0.00327,"epssPercentile":0.22992,"slug":"CVE-2026-54450","body":"## Overview\n\nToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.29.1, networking.IsPrivateIP in pkg/networking/utilities.go omits the IPv6 NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48, so NAT64 addresses embedding private, loopback, or link-local IPv4 targets are classified as public and allowed. The most direct attacker-controlled path begins when an external OAuth client supplies a client_id URL that CIMDStorageDecorator.GetClient routes through FetchClientMetadataDocument in pkg/oauthproto/cimd/fetch.go; protectedDialerControl in pkg/networking/http_client.go and validateHost in pkg/skills/gitresolver/reference.go share the defective classification but use operator-controlled or user-controlled destinations. On a ToolHive host behind a NAT64/DNS64 gateway, the gateway translates an allowed address such as 64:ff9b:1::a9fe:a9fe to 169.254.169.254, permitting blind probing of internal TCP or TLS reachability. The attacker-controlled CIMD path requires HTTPS, verifies certificates, and does not reflect response bodies, so the established impact is an internal reachability oracle rather than metadata credential exfiltration; the webhook client is not affected because it does not use this IP guard. This issue is fixed in version 0.29.1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-54450)\n\nAffected packages:\n\n- `github.com/stacklok/toolhive <= 0.29.0`\n\nPatched in:\n\n- `github.com/stacklok/toolhive 0.29.1`\n\nSource: https://github.com/advisories/GHSA-pph6-vfjv-vpjw","depth":"sunlit","depthScore":16,"depthScoreParts":{"impact":16,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":204265,"id":"CVE-2026-54450","ts":1789490437649,"field":"cvss","old":null,"new":"2.9"}]}