CVE-2026-61568: @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport

Published Sep 15, 2026
·
Updated

@zereight/mcp-gitlab is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route browser requests to a victim's local MCP listener while preserving an attacker-controlled Host and Origin. The server accepts those headers and reaches the MCP initialization path instead of rejecting the request at the HTTP boundary. Version 2.1.30 contains a patch.

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade @zereight/mcp-gitlab to a version that resolves this vulnerability.

    Fixed in 2.1.30

Event History

Sep 15, 2026
CVE Published
via MITRE·08:56 PM
Data Sourced
via MITRE·08:56 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Users running @zereight/mcp-gitlab versions earlier than 2.1.30 with the Streamable HTTP MCP endpoint reachable on their local listener are exposed to browser-based DNS rebinding attempts.

2

What does an attacker need to exploit it?

An attacker needs to induce a victim to visit a malicious web page. The attack uses DNS rebinding so browser requests are routed to the victim's local MCP listener while retaining attacker-controlled Host and Origin headers.

3

Are default HTTP header checks sufficient to block the attack?

No. Affected versions do not enforce an effective Host or Origin allowlist, so the server accepts attacker-controlled headers and proceeds into MCP initialization rather than rejecting the request at the HTTP boundary.

4

What is the remediation?

Upgrade @zereight/mcp-gitlab to version 2.1.30, which contains the patch.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203