mediumVulnerability

GHSA-c9xm-49cp-xcr9

## Summary The `rmcp` OAuth client accepts a server-controlled `resource_metadata=` URL from the `WWW-Authenticate` header and fetches it without same-origin or private-network validation. An attacker-controlled MCP server can return a `401 WWW-Authenticate: Bearer resource_metadata="..."` header pointing at an internal URL, including localhost, RFC 1918 addresses, or cloud metadata endpoints. The client then performs an outbound GET to that URL from the victim application's network context. ## Affected version - Repository: `modelcontextprotocol/rust-sdk` - Crate: `rmcp` - Current `main` reviewed: `c330fede90e4729c234f8e87fdbc5ea27a1dd10c` - Commit date: 2026-05-19 - Affected file: `crates/rmcp/src/transport/auth.rs` - File blob: `3aa3e91310662c409af9dc38c9d584d6df217e9c` - Severity framing: High/Medium SSRF, depending on the embedding application's network position and whether response parsing gives the attacker useful success/failure or chained fetch behavior. ## Source evidence `extract_www_authenticate_params()` accepts an absolute URL from the server-controlled header: ```rust let resource_key = "resource_metadata="; while let Some(pos) = header_lowercase[search_offset..].find(resource_key) { let global_pos = search_offset + pos + resource_key.len(); let value_slice = &header[global_pos..]; if let Some((value, consumed)) = Self::parse_next_header_value(value_slice) { if let Ok(url) = Url::parse(&value) { params.resource_metadata_url = Some(url); break; } if let Ok(url) = base_url.join(&value) { params.resource_metadata_url = Some(url); break; } ``` There is no check that the parsed URL shares origin with the original MCP server, and no block for loopback, link-local, RFC 1918, or metadata hostnames. `fetch_resource_metadata_from_url()` then performs the GET: ```rust let response = match self .http_client .get(resource_metadata_url.clone()) .header(

Properties

ghsa_id
GHSA-c9xm-49cp-xcr9
severity
medium
summary
rmcp OAuth client fetches server-controlled resource_metadata URLs
last_source
GitHub Advisory Database
cve_id
GHSA-c9xm-49cp-xcr9
signal_observed_at
2026-10-02T19:33:52+00:00
is_ghsa_only
true
retrieved_at
2026-10-02T19:33:52+00:00
ghsa_published
2026-10-02T16:12:31Z
source_url
https://github.com/advisories/GHSA-c9xm-49cp-xcr9
ghsa_updated
2026-10-02T16:12:32Z

Related Entities (4)

VULNERABLE_TO (1)

←[Software]rust/rmcp

AFFECTS (1)

→[Software]rust/rmcp

HAS_WEAKNESS (1)

→[Weakness]Server-Side Request Forgery (SSRF)

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-c9xm-49cp-xcr9 — Ninja Signal Threat Intelligence | Ninja Signal