Junglewise Threat Intelligence

sooperset mcp-atlassian DNS-rebinding SSRF bypass in URL validation

Severity: medium · CVSS 6.5 · Published 2026-07-10

Technologies: Sooperset Mcp-Atlassian, mcp-atlassian (PyPI). Vendors: Sooperset, PyPI.

Executive brief

A vulnerability in the mcp-atlassian library allows attackers to bypass security checks and access internal network resources or cloud metadata. The software attempts to verify that a web address is safe before connecting to it, but a timing flaw allows an attacker to swap the safe address for a malicious one (such as an internal server) immediately after the check passes. This could lead to the exposure of sensitive internal data or cloud credentials.

Technical details

The vulnerability exists in the `validate_url_for_ssrf` function within `src/mcp_atlassian/utils/urls.py`. While the middleware resolves and validates the IP address of a provided hostname from the `X-Atlassian-Jira-Url` or `X-Atlassian-Confluence-Url` headers, it does not pin the validated IP to the subsequent connection. An attacker can use a DNS-rebinding technique where the first resolution returns a benign public IP to pass the guard, but the second resolution at connect-time returns a sensitive internal IP (e.g., 169.254.169.254). This allows for unauthenticated SSRF against internal services or cloud metadata endpoints. The issue is addressed in version 0.22.0.

Affected products

  • sooperset mcp-atlassian < 0.22.0

Timeline

  • 2026-07-10: advisory: GitHub Advisory GHSA-489g-7rxv-6c8q published
  • 2026-07-10: patched: Version 0.22.0 released

References

Related threats