Executive brief
Kuadrant MCP Gateway is a tool used to manage and secure connections between different software services. A security flaw allows unauthorized users to bypass identity checks and gain access to internal or external services connected to the gateway. This could lead to unauthorized data access or the ability to perform actions on behalf of the system, potentially compromising sensitive integrations like GitHub Copilot.
Technical details
The MCP router (ext_proc) contains an 'initialize' method code path that fails to properly validate requests when an 'mcp-init-host' header is present. This flaw allows an attacker to bypass the JWT session validator and rewrite the upstream ':authority' header. The attack is gated by a 'router-key' which is either a hardcoded default ('secret-api-key') or a SHA-256 truncation of a non-secret resource UID visible in process arguments. Successful exploitation allows an unauthenticated network attacker to forward requests to any registered backend listener, bypassing both the broker's capability filters and the gateway's session model. As of the advisory date, no patched version is specified for versions <= 0.6.1.
Affected products
- Kuadrant mcp-gateway <= 0.6.1
Timeline
- 2026-05-13: disclosed: Vulnerability reported to Kuadrant
- 2026-05-19: advisory: GitHub Advisory published