GHSA-c9xm-49cp-xcr9Medium▾ Sunlitrmcp OAuth client fetches server-controlled resource_metadata URLs
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The rmcp OAuth client accepts a server-controlled resource_metadata= URL from the WWW-Authenticate header and fetches it without same-origin or private-network validation.
An attacker-controlled MCP server can return a 401 WWW-Authenticate: Bearer resource_metadata="..." header pointing at an internal URL, including localhost, RFC 1918 addresses, or cloud metadata endpoints. The client then performs an outbound GET to that URL from the victim application's network context.
modelcontextprotocol/rust-sdkrmcpmain reviewed: c330fede90e4729c234f8e87fdbc5ea27a1dd10ccrates/rmcp/src/transport/auth.rs3aa3e91310662c409af9dc38c9d584d6df217e9cextract_www_authenticate_params() accepts an absolute URL from the server-controlled header:
let resource_key = "resource_metadata=";
while let Some(pos) = header_lowercase[search_offset..].find(resource_key) {
let global_pos = search_offset + pos + resource_key.len();
let value_slice = &header[global_pos..];
if let Some((value, consumed)) = Self::parse_next_header_value(value_slice) {
if let Ok(url) = Url::parse(&value) {
params.resource_metadata_url = Some(url);
break;
}
if let Ok(url) = base_url.join(&value) {
params.resource_metadata_url = Some(url);
break;
}
There is no check that the parsed URL shares origin with the original MCP server, and no block for loopback, link-local, RFC 1918, or metadata hostnames.
fetch_resource_metadata_from_url() then performs the GET:
let response = match self
.http_client
.get(resource_metadata_url.clone())
.header(HEADER_MCP_PROTOCOL_VERSION, "2024-11-05")
.send()
.await
Again, there is no same-origin, scheme, host, DNS, or IP-range validation before the request.
rmcp connects to an attacker-controlled MCP server, or to a compromised MCP server.401 and a WWW-Authenticate header such as:WWW-Authenticate: Bearer resource_metadata="http://169.254.169.254/latest/meta-data/"
resource_metadata value as a URL.This can be used to probe internal services. In environments where the target endpoint returns JSON matching the expected metadata shape, the flow can also chain into additional authorization-server metadata fetches.
The direct impact is SSRF from any application embedding the rmcp OAuth client. Depending on where the client runs, this can reach:
The attacker controls the URL through the MCP server response. The victim only needs to connect to the attacker's MCP server or a compromised server that can emit the crafted WWW-Authenticate header.
On 2026-05-27:
GHSA-9g45-5xwm-f3wc: custom HTTP headers leak to cross-origin redirect targets.GHSA-89vp-x53w-74fx: DNS rebinding in Streamable HTTP server transport.WWW-Authenticate resource_metadata SSRF returned no open or closed matches.resource_metadata returned one closed implementation issue, #517, about authorization discovery fallback behavior, not SSRF/resource validation.This report is distinct from the redirect-header advisory and the DNS-rebinding advisory.
Before accepting or fetching a resource_metadata URL:
A minimal same-origin check would compare scheme, host, and effective port:
fn is_same_origin(base: &Url, candidate: &Url) -> bool {
base.scheme() == candidate.scheme()
&& base.host() == candidate.host()
&& base.port_or_known_default() == candidate.port_or_known_default()
}
If cross-origin resource_metadata is required for compatibility, it should be explicitly opted into and protected by private-network blocking.
rmcp < 2.0.0Upgrade to a patched release:
rmcp 2.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-68616High· 7.5WeasyPrint helps web developers to create PDF documents
CVE-2021-21985Critical· 9.8The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server
CVE-2021-26855Critical· 9.1Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-34473Critical· 9.1Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2024-21893High· 8.2A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without auth…
CVE-2023-26735High· 7.5blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface