Impact
ToolHive, a utility for deploying Model Context Protocol servers, has an SSRF guard that mistakenly treats IPv6 NAT64 addresses for the prefixes 64:ff9b::/96 and 64:ff9b:1::/48 as public, even though they map to private, loopback, or link-local IPv4 targets. This is a CWE-918 server‑side request forgery vulnerability. This misclassification allows an attacker to supply a client_id URL through an external OAuth client, leading to a fetch of internal metadata behind a NAT64/DNS64 gateway. The gateway translates the allowed NAT64 address to the private address 169.254.169.254, permitting blind probing of internal TCP or TLS reachability. The request proceeds over HTTPS, verifies certificates, and does not reflect response bodies, so the effect is an internal reachability oracle rather than credential exfil because it does not use the IP guard, and the issue is fixed in ToolHive 0.29.1.
Affected Systems
The vulnerability affects Stacklok’s ToolHive utility, any installation earlier than version 0.29.1.
Risk and Exploitability
The CVSS score of 2.9 reflects a low‑severity issue, and the EPSS score is < 1%. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit it from the outside by directing an external OAuth client ID to a URL that resolves to a NAT64‑translated internal address; the process requires HTTPS with certificate validation but does not rely on privileged operations, making exploitation straightforward in a NAT64 environment.
OpenCVE Enrichment
Github GHSA