Junglewise Threat Intelligence

CVE-2026-73497: MCP Atlassian DNS rebinding SSRF via header validation bypass

CVE-2026-73497 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: Sooperset MCP Atlassian. Vendors: Sooperset.

Executive brief

MCP Atlassian is a server that bridges AI models to Atlassian products like Jira and Confluence. A flaw allows attackers to make unauthenticated requests to cloud metadata services (such as AWS EC2 metadata) or internal company networks by exploiting a DNS rebinding technique. An attacker can trick the validation logic to accept a legitimate IP address during the initial check, then provide a different internal IP address during the actual connection.

Technical details

The vulnerability is a TOCTOU (time-of-check-time-of-use) flaw in SSRF validation spanning src/mcp_atlassian/utils/urls.py, src/mcp_atlassian/servers/main.py, and src/mcp_atlassian/servers/dependencies.py. The validate_url_for_ssrf function validates the attacker-controlled X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url headers once at middleware time, resolving the hostname and confirming it is not a private IP or metadata endpoint. However, the Jira and Confluence fetchers use the raw hostname without IP pinning, causing a second DNS resolution at connection time. An attacker with control over DNS can return a public IP during validation and 169.254.169.254 (AWS metadata) or another internal IP during connection, bypassing SSRF protections. No authentication is required. The issue affects versions 0.17.0 through 0.22.0 (exclusive) and is fixed in 0.22.0 via the SsrfPinningAdapter that resolves each host once and connects to the pinned address.

Affected products

  • sooperset MCP Atlassian 0.17.0 to 0.22.0 (fixed in 0.22.0)

Timeline

  • 2026-09-14: disclosed
  • 2026-07-10: patched: Fix landed in version 0.22.0

References