---
id: CVE-2026-54450
title: >-
  ToolHive is a utility designed to simplify the deployment and management of
  Model Context Protocol (MCP) servers
summary: >-
  ToolHive is a utility designed to simplify the deployment and management of
  Model Context Protocol (MCP) servers. Prior to 0.29.1, networking.IsPrivateIP
  in pkg/networking/utilities.go omits the IPv6 NAT64 prefixes 64:ff9b::/96 and
  64:ff…
severity: low
cvss: 2.9
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'
cwe:
  - CWE-918
vendor: stacklok
product: toolhive
affected:
  - toolhive < 0.29.1
patched:
  - github.com/stacklok/toolhive 0.29.1
published: '2026-09-15'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T17:17:20.480'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-54450'
references:
  - url: >-
      https://github.com/stacklok/toolhive/commit/26912af453d2040787983dbc9ab93a9019ec0468
    label: security-advisories@github.com
  - url: 'https://github.com/stacklok/toolhive/releases/tag/v0.29.1'
    label: security-advisories@github.com
  - url: >-
      https://github.com/stacklok/toolhive/security/advisories/GHSA-pph6-vfjv-vpjw
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-pph6-vfjv-vpjw'
tags:
  - nvd
  - cve.org
  - ghsa
  - go
aliases:
  - GHSA-pph6-vfjv-vpjw
ecosystem: go
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T16:12:58.689222Z'
cvssSource: cna
ingestedAt: '2026-07-15T22:46:58.967Z'
epss: 0.00327
epssPercentile: 0.23084
---

## Overview

ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.29.1, networking.IsPrivateIP in pkg/networking/utilities.go omits the IPv6 NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48, so NAT64 addresses embedding private, loopback, or link-local IPv4 targets are classified as public and allowed. The most direct attacker-controlled path begins when an external OAuth client supplies a client_id URL that CIMDStorageDecorator.GetClient routes through FetchClientMetadataDocument in pkg/oauthproto/cimd/fetch.go; protectedDialerControl in pkg/networking/http_client.go and validateHost in pkg/skills/gitresolver/reference.go share the defective classification but use operator-controlled or user-controlled destinations. On a ToolHive host behind a NAT64/DNS64 gateway, the gateway translates an allowed address such as 64:ff9b:1::a9fe:a9fe to 169.254.169.254, permitting blind probing of internal TCP or TLS reachability. The attacker-controlled CIMD path requires HTTPS, verifies certificates, and does not reflect response bodies, so the established impact is an internal reachability oracle rather than metadata credential exfiltration; the webhook client is not affected because it does not use this IP guard. This issue is fixed in version 0.29.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-54450)

Affected packages:

- `github.com/stacklok/toolhive <= 0.29.0`

Patched in:

- `github.com/stacklok/toolhive 0.29.1`

Source: https://github.com/advisories/GHSA-pph6-vfjv-vpjw
