Description
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). From 0.17.0 until 0.22.0, validate_url_for_ssrf resolves the attacker-controlled X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url header host once at middleware time, but the outbound request is built with the raw hostname and resolves it again at connection time with no IP pinning. An attacker-controlled DNS-rebinding name can return a public IP during validation and 169.254.169.254 or another internal IP during connection, enabling unauthenticated server-side requests to cloud metadata or internal services. The flaw spans src/mcp_atlassian/utils/urls.py, src/mcp_atlassian/servers/main.py, and src/mcp_atlassian/servers/dependencies.py; validate_url_for_ssrf returns only a verdict rather than a pinned IP, UserTokenMiddleware processes the attacker-controlled headers before fetcher creation, and the Jira and Confluence fetchers use the raw hostname. This issue is fixed in version 0.22.0.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery
Action: Patch
AI Analysis

Impact

The MCP‑Atlassian server validates the X‑Atlassian‑Jira‑Url and X‑Atlassian‑Confluence‑Url headers only once at middleware time; the outbound request is constructed with the raw hostname and resolved again at connection time without IP pinning. An attacker can perform DNS‑rebinding so that the first resolution points to a public IP, while the second resolution points to an internal IP such as the cloud metadata service 169.254.169.254 or other private addresses. This allows an unauthenticated server‑side request to sensitive internal or cloud metadata resources, exposing confidential data. The vulnerability is identified as a Server‑Side Request Forgery (CWE‑918).

Affected Systems

The affected product is the MCP‑Atlassian server for Atlassian Confluence and Jira, distributed by Sooperset. Versions from 0.17.0 until (but not including) 0.22 in release 0.22.0; any deployment of an earlier version is impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates medium the vulnerability is not listed in the KEV catalog. Despite the medium CVSS score, the EPSS score of <1% indicates a very low probability of exploitation. The flaw allows an attacker who can reach the MCP‑Atlassian server to cause the server to resolve a DNS‑rebinding name differently at validation and at connection time, enabling unauthenticated server‑side requests to internal addresses such as 169.254.169.254. While no official exploitation statistics are publicly reported, the lack of authentication combined with the potential to access internal services suggests a moderate exploitation risk. Attackers would need network access to the MCP server, but no additional privileges are required.

Generated by OpenCVE AI on September 20, 2026 at 22:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the MCP‑Atlassian server to version 0.22.0 or later to receive the fixed validation logic and hostname pinning.
  • Configure the server to reject or strip the X‑Atlassian‑Jira‑Url and X‑Atlassian‑Confluence‑Url headers unless coming from a trusted source, thereby reducing the attack surface for header‑based SSRF.
  • Implement DNS rebinding protection or enforce strict inbound hostname validation so that any DNS rebinding attempts resolve to disallowed internal IP ranges before request creation.

Generated by OpenCVE AI on September 20, 2026 at 22:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Sooperset
Sooperset mcp-atlassian
Vendors & Products Sooperset
Sooperset mcp-atlassian

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). From 0.17.0 until 0.22.0, validate_url_for_ssrf resolves the attacker-controlled X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url header host once at middleware time, but the outbound request is built with the raw hostname and resolves it again at connection time with no IP pinning. An attacker-controlled DNS-rebinding name can return a public IP during validation and 169.254.169.254 or another internal IP during connection, enabling unauthenticated server-side requests to cloud metadata or internal services. The flaw spans src/mcp_atlassian/utils/urls.py, src/mcp_atlassian/servers/main.py, and src/mcp_atlassian/servers/dependencies.py; validate_url_for_ssrf returns only a verdict rather than a pinned IP, UserTokenMiddleware processes the attacker-controlled headers before fetcher creation, and the Jira and Confluence fetchers use the raw hostname. This issue is fixed in version 0.22.0.
Title MCP Atlassian is a Model Context Protocol (MCP): DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826): unauthenticated SSRF to cloud metadata
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Sooperset Mcp-atlassian
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T13:56:00.939Z

Reserved: 2026-08-12T19:00:33.736Z

Link: CVE-2026-73497

cve-icon Vulnrichment

Updated: 2026-09-15T13:25:25.667Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T20:16:50.993

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-73497

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:30:06Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)