Description
ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.31.0, remote.Handler.Authenticate in pkg/auth/remote/handler.go invokes discovery.DetectAuthenticationFromServer in pkg/auth/discovery/discovery.go, whose host-side HTTP clients trust remote-server-controlled authentication discovery destinations, follow redirects without host or scheme restrictions, and do not consistently block private addresses. A malicious or compromised remote MCP server can place a resource_metadata URL in WWW-Authenticate for ParseWWWAuthenticate to extract, after which FetchResourceMetadata, OIDC issuer discovery, and well-known discovery can issue GET requests to link-local, RFC1918, or other internal services outside the server's container. The user connects to a server that the user intends to use, but the server controls the internal destination; this path does not depend on the separate NAT64 guard omission because the affected clients did not invoke IsPrivateIP, and it differs from the DCR resolver path that already refused redirects. The demonstrated primitive reaches internal-only HTTP services and reachability or error oracles, and can retrieve AWS metadata credentials where IMDSv1 accepts an unauthenticated GET, while IMDSv2 and GCP metadata prerequisites are not satisfied by the demonstrated request. This vulnerability is fixed in 0.31.0.
Published: 2026-09-15
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SSRF
Action: Apply Patch
AI Analysis

Impact

ToolHive's authentication discovery routine accepts a WWW-Authenticate header with an embedded URL, blindly follows any redirects from the server, and lacks restrictions on destination host or scheme. This permits a malicious MCP server to instruct the client to contact any address reachable from the client, including link‑local, RFC1918, or provider metadata services, thereby enabling internal reconnaissance and extraction of short‑lived credentials. The flaw is identified as CWE‑918, a server‑side request forgery mechanism that undermines confidentiality of internal infrastructure. The CVSS score of 4.7 indicates moderate severity; the EPSS score is <1% and the vulnerability is not listed in CISA KEV, implying a low but non-zero exploitation risk.

Affected Systems

All releases of ToolHive built by Stacklok prior to version 0.31.0 are affected. The issue exists in the pkg/auth/remote/handler.go and pkg/auth/discovery/discovery.go modules that perform authentication discovery during client initialization. Users running those defaults are vulnerable until the update is applied.

Risk and Exploitability

The vulnerability requires an attacker to control or compromise a remote MCP server that a client will connect to. Once such a server responds with a crafted WWW-Authenticate header containing a resource_metadata URL, the client will issue HTTP GET requests to that address, following redirects without host or scheme validation. The exploit path does not rely on NAT64 guard omission; it directly bypasses container isolation for the client. Successful exploitation can reveal the presence of internal web services, expose AWS IMDSv1 metadata points, or enumerate other internal endpoints, providing opportunities for credential theft. The potential impact is limited to the connectivity of the affected client; however, any client that authenticates against the malicious server can be used as a foothold to probe the internal network. The CVSS score of 4.7 indicates moderate severity, and the EPSS score is reported as <1%, implying a low yet non-zero exploitation probability. It is not listed in CISA KEV.

Generated by OpenCVE AI on September 20, 2026 at 16:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ToolHive to 0.31.0 or later to apply the vendor patch that blocks private addresses and unguarded redirects.
  • Configure the client or environment to restrict outbound HTTP traffic to only public or controlled domains, blocking RFC1918, link‑local, and other internal IP ranges.
  • If upgrade is not immediately feasible, disable the authentication discovery feature in ToolHive or patch the client code to reject any WWW-Authenticate header that points to non‑public hosts.

Generated by OpenCVE AI on September 20, 2026 at 16:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-pr64-jmmf-jp54 ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation)
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Stacklok
Stacklok toolhive
Vendors & Products Stacklok
Stacklok toolhive

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.31.0, remote.Handler.Authenticate in pkg/auth/remote/handler.go invokes discovery.DetectAuthenticationFromServer in pkg/auth/discovery/discovery.go, whose host-side HTTP clients trust remote-server-controlled authentication discovery destinations, follow redirects without host or scheme restrictions, and do not consistently block private addresses. A malicious or compromised remote MCP server can place a resource_metadata URL in WWW-Authenticate for ParseWWWAuthenticate to extract, after which FetchResourceMetadata, OIDC issuer discovery, and well-known discovery can issue GET requests to link-local, RFC1918, or other internal services outside the server's container. The user connects to a server that the user intends to use, but the server controls the internal destination; this path does not depend on the separate NAT64 guard omission because the affected clients did not invoke IsPrivateIP, and it differs from the DCR resolver path that already refused redirects. The demonstrated primitive reaches internal-only HTTP services and reachability or error oracles, and can retrieve AWS metadata credentials where IMDSv1 accepts an unauthenticated GET, while IMDSv2 and GCP metadata prerequisites are not satisfied by the demonstrated request. This vulnerability is fixed in 0.31.0.
Title ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation)
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Subscriptions

Stacklok Toolhive
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T17:27:27.029Z

Reserved: 2026-06-29T17:09:25.871Z

Link: CVE-2026-58196

cve-icon Vulnrichment

Updated: 2026-09-15T17:27:23.619Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:16.817

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-58196

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:15:18Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)