Get a demo — 30 minutes →
← Back to blog
Anomity robot illustrating GitLab MCP CVE-2026-61568 - Streamable HTTP DNS Rebinding to Localhost
AdvisoryCritical

GitLab MCP CVE-2026-61568 - Streamable HTTP DNS Rebinding to Localhost

MCP Server Security·Critical·CVE-2026-61568 (CVSS 9.6, GHSA-vmp7-252j-cwp7)·
Affected @zereight/mcp-gitlab before 2.1.30 (Streamable HTTP /mcp without Host/Origin DNS-rebinding controls)

CVE-2026-61568 (GHSA-vmp7-252j-cwp7) hits @zereight/mcp-gitlab, a widely used npm MCP server for GitLab. Its Streamable HTTP endpoint accepted attacker-controlled Host and Origin headers because the SDK DNS-rebinding knobs were never enabled. Default bind 127.0.0.1 is exactly what DNS rebinding is for. Fixed in 2.1.30; GHSA published 15 September 2026. CVSS 9.6.

The missing allowlist

The vulnerable setup created StreamableHTTPServerTransport with a session id generator and metrics hooks - and without enableDnsRebindingProtection, allowedHosts, or allowedOrigins. Express JSON parsing sat globally before any Host/Origin gate on /mcp. A malicious page that rebinds DNS to the victim's loopback can therefore speak MCP to the local listener while preserving attacker-chosen headers.

Once a session initializes, impact depends on credentials already available to the MCP process. With a GitLab token present, tools such as list_project_variables can pull CI/CD secrets. That is not a theoretical side channel: it is the documented tool surface of a GitLab MCP. Adjacent MCP HTTP failures - LiteLLM MCP OAuth passthrough, AI gateway OAuth passthrough anti-patterns, and network-ai empty-secret cross-origin MCP - rhyme for the same reason: HTTP boundaries on MCP are security-critical, not cosmetic.

Why REMOTE_AUTHORIZATION is not the fix

The package documents REMOTE_AUTHORIZATION=true for multi-user HTTP deployments. In that mode, unauthenticated tools/list and material GitLab API calls are blocked by token checks. Useful - and incomplete. The Host/Origin defect remains at the browser boundary: the server still accepts attacker-controlled headers and processes initialize instead of rejecting cross-origin localhost access. Authz after a poisoned session start is not the same as refusing the session.

  • Upgrade to @zereight/mcp-gitlab 2.1.30+ (PR #555 / commit 52207c6f enables DNS-rebinding protection and restricts allowed hosts/origins).
  • Prefer stdio for single-user local agent wiring when Streamable HTTP is unnecessary.
  • Assume loopback HTTP MCP is browser-reachable until Host/Origin allowlists are proven on.
  • Rotate GitLab tokens and CI variables if a vulnerable listener was active during browser use of untrusted sites.
  • Inventory localhost MCP ports across developer endpoints - they rarely appear in vulnerability scanners aimed at prod.

Read alongside MySQL MCP SSE DNS rebinding CVE-2026-59971 and the class analysis of local MCP HTTP DNS rebinding. Same SDK features, same forgotten enable flags.

How Anomity governs local GitLab MCP HTTP

Anomity's Endpoint Sensor inventories MCP servers and agents on each managed endpoint so @zereight/mcp-gitlab versions and HTTP listeners are visible fleet-wide. Browser Sensor and cloud discovery cover adjacent AI OAuth surfaces. At the agent hook (for example Claude Code PreToolUse), runtime governance can deny sensitive GitLab tool calls before they run, with a 90-day audit trail to SIEM, Slack, email, or Jira. SOC 2 Type II; complements Network, EDR, DLP, and GRC.

Upgrade to 2.1.30, treat localhost MCP HTTP as a browser trust boundary, and request early access to inventory which Streamable HTTP listeners your developers actually left open.

Frequently asked questions

Am I affected by CVE-2026-61568?

You are in scope if any endpoint runs @zereight/mcp-gitlab before 2.1.30 with the Streamable HTTP transport enabled. Confirm package version and whether developers pointed agents at a local /mcp HTTP URL rather than stdio-only wiring.

Does REMOTE_AUTHORIZATION mitigate this?

It reduces unauthenticated tools/list and material GitLab API tool calls when tokens are required. It does not reject attacker-controlled Host or Origin headers at the HTTP boundary, so MCP initialize can still succeed via DNS rebinding. Treat auth middleware and Host/Origin allowlists as separate controls.

What is the CVSS vector?

GLAD publishes CVSS 9.6 Critical with CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H. User interaction is present (victim browses an attacker page), but impact remains high confidentiality, integrity, and availability with scope change when GitLab tools and tokens are reachable.

What should teams do first?

Upgrade to 2.1.30 or later everywhere the package is installed. Prefer stdio for local agent use when HTTP is unnecessary. Inventory local MCP HTTP listeners and GitLab tokens on developer machines. Rotate CI variables if a pre-fix Streamable HTTP listener was reachable from a browser session.

How does Anomity help?

Anomity inventories MCP servers and related CLIs on managed endpoints so localhost Streamable HTTP listeners and package versions become visible. Runtime governance can deny sensitive tools/call paths at the agent hook before they run, with a 90-day audit trail to SIEM, Slack, email, or Jira. Metadata only; secrets redacted on-endpoint. Complements Network, EDR, DLP, and GRC.

Ask AI about Anomity
ChatGPT Claude Perplexity Google AI Grok