{"id":"GHSA-g53w-w6mj-hrpp","aliases":["GO-2026-5390"],"title":"MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin \"router-key\" / \"mcp-init-host\" path","summary":"MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin \"router-key\" / \"mcp-init-host\" path","severity":"critical","vendor":"Kuadrant","product":"github.com/Kuadrant/mcp-gateway","ecosystem":"go","affected":["github.com/Kuadrant/mcp-gateway < 0.7.0"],"patched":["github.com/Kuadrant/mcp-gateway 0.7.0"],"published":"2026-05-19","updated":"2026-07-21","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-g53w-w6mj-hrpp","references":[{"url":"https://github.com/Kuadrant/mcp-gateway/security/advisories/GHSA-g53w-w6mj-hrpp"},{"url":"https://github.com/Kuadrant/mcp-gateway/commit/6052079283472aff99727058c92618178f86b2d7"},{"url":"https://github.com/Kuadrant/mcp-gateway"},{"url":"https://github.com/Kuadrant/mcp-gateway/releases/tag/v0.7.0"}],"tags":["osv","go"],"ingestedAt":"2026-07-21T19:04:58.952Z","slug":"GHSA-g53w-w6mj-hrpp","body":"## Overview\n\n## Summary\n \nThe MCP router (ext_proc) exposes an `initialize`-method code path that, when a\nrequest carries an `mcp-init-host` header, bypasses the gateway JWT session\nvalidator and rewrites the upstream `:authority` header to whatever the caller\nchooses, gated only by a single shared header value (`router-key`). The shared\nvalue is\n\n* a literal string (`secret-api-key`) baked into `cmd/mcp-broker-router/main.go`\n  as a fall-back default, and\n* in controller-managed deployments, a SHA-256 truncation of the\n  `MCPGatewayExtension` UID — a non-secret value visible to anyone with `get`\n  permission on the resource, and additionally exposed in `argv` because it is\n  passed to the broker-router container via `--mcp-router-key=...`.\n\nA request that satisfies the trivial header check is forwarded to any backend\nlistener registered with the gateway (including external services such as\n`api.githubcopilot.com` when configured), bypassing both the broker (where the\nsigned `x-mcp-authorized` capability filter is enforced) and the gateway's\nJWT-based session model.\n\n## Affected packages\n\n- `github.com/Kuadrant/mcp-gateway < 0.7.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/Kuadrant/mcp-gateway 0.7.0`","depth":"midnight","depthScore":52,"depthScoreParts":{"impact":52.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}