VYPR
Critical severityNVD Advisory· Published May 27, 2026· Updated Jun 17, 2026

CVE-2026-9739

CVE-2026-9739

Description

Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented allowed-origins and allowed-hosts flags to align with MCP security guidelines. However, the hardcoded Access-Control-Allow-Origin: * header in the SSE initialization handler was inadvertently retained. This vulnerability specifically impacts users connecting via Toolbox using SSE under specification v2024-11-05.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/googleapis/mcp-toolboxGo
< 1.2.01.2.0

Affected products

3

Patches

Vulnerability mechanics

References

5

News mentions

2