{"id":"CVE-2026-73497","title":"MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)","summary":"MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). From 0.17.0 until 0.22.0, validate_url_for_ssrf resolves the attacker-controlled X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url hea…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","cwe":["CWE-918"],"vendor":"sooperset","product":"mcp-atlassian","affected":["mcp-atlassian >= 0.17.0, < 0.22.0"],"published":"2026-09-14","updated":"2026-09-15","sourceUpdated":"2026-09-15T14:17:08.457","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73497","references":[{"url":"https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460","label":"security-advisories@github.com"},{"url":"https://github.com/sooperset/mcp-atlassian/pull/1448","label":"security-advisories@github.com"},{"url":"https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0","label":"security-advisories@github.com"},{"url":"https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-489g-7rxv-6c8q","label":"security-advisories@github.com"},{"url":"https://github.com/sooperset/mcp-atlassian"}],"tags":["nvd","cve.org","osv","pip"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-15T13:25:24.644811Z"},"epss":0.00232,"epssPercentile":0.14308,"ingestedAt":"2026-09-14T20:14:21.155Z","aliases":["GHSA-489g-7rxv-6c8q"],"ecosystem":"pip","patched":["mcp-atlassian 0.22.0"],"slug":"CVE-2026-73497","body":"## Overview\n\nMCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). From 0.17.0 until 0.22.0, validate_url_for_ssrf resolves the attacker-controlled X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url header host once at middleware time, but the outbound request is built with the raw hostname and resolves it again at connection time with no IP pinning. An attacker-controlled DNS-rebinding name can return a public IP during validation and 169.254.169.254 or another internal IP during connection, enabling unauthenticated server-side requests to cloud metadata or internal services. The flaw spans src/mcp_atlassian/utils/urls.py, src/mcp_atlassian/servers/main.py, and src/mcp_atlassian/servers/dependencies.py; validate_url_for_ssrf returns only a verdict rather than a pinned IP, UserTokenMiddleware processes the attacker-controlled headers before fetcher creation, and the Jira and Confluence fetchers use the raw hostname. This issue is fixed in version 0.22.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-73497)\n\nAffected packages:\n\n- `mcp-atlassian < 0.22.0`\n\nPatched in:\n\n- `mcp-atlassian 0.22.0`\n\nSource: https://osv.dev/vulnerability/GHSA-489g-7rxv-6c8q","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}