GHSA-c9xm-49cp-xcr9
## Summary The `rmcp` OAuth client accepts a server-controlled `resource_metadata=` URL from the `WWW-Authenticate` header and fetches it without same-origin or private-network validation. An attacker-controlled MCP server can return a `401 WWW-Authenticate: Bearer resource_metadata="..."` header pointing at an internal URL, including localhost, RFC 1918 addresses, or cloud metadata endpoints. The client then performs an outbound GET to that URL from the victim application's network context. ## Affected version - Repository: `modelcontextprotocol/rust-sdk` - Crate: `rmcp` - Current `main` reviewed: `c330fede90e4729c234f8e87fdbc5ea27a1dd10c` - Commit date: 2026-05-19 - Affected file: `crates/rmcp/src/transport/auth.rs` - File blob: `3aa3e91310662c409af9dc38c9d584d6df217e9c` - Severity framing: High/Medium SSRF, depending on the embedding application's network position and whether response parsing gives the attacker useful success/failure or chained fetch behavior. ## Source evidence `extract_www_authenticate_params()` accepts an absolute URL from the server-controlled header: ```rust let resource_key = "resource_metadata="; while let Some(pos) = header_lowercase[search_offset..].find(resource_key) { let global_pos = search_offset + pos + resource_key.len(); let value_slice = &header[global_pos..]; if let Some((value, consumed)) = Self::parse_next_header_value(value_slice) { if let Ok(url) = Url::parse(&value) { params.resource_metadata_url = Some(url); break; } if let Ok(url) = base_url.join(&value) { params.resource_metadata_url = Some(url); break; } ``` There is no check that the parsed URL shares origin with the original MCP server, and no block for loopback, link-local, RFC 1918, or metadata hostnames. `fetch_resource_metadata_from_url()` then performs the GET: ```rust let response = match self .http_client .get(resource_metadata_url.clone()) .header(
Properties
- ghsa_id
- GHSA-c9xm-49cp-xcr9
- severity
- medium
- summary
- rmcp OAuth client fetches server-controlled resource_metadata URLs
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-c9xm-49cp-xcr9
- signal_observed_at
- 2026-10-02T19:33:52+00:00
- is_ghsa_only
- true
- retrieved_at
- 2026-10-02T19:33:52+00:00
- ghsa_published
- 2026-10-02T16:12:31Z
- source_url
- https://github.com/advisories/GHSA-c9xm-49cp-xcr9
- ghsa_updated
- 2026-10-02T16:12:32Z
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph