{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3asoopersetmcp-atlassian/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:sooperset:mcp-atlassian:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-77274"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["mcp-atlassian (\u003c 0.22.0)"],"_cs_severities":["high"],"_cs_tags":["ssrf","application-vulnerability","lfd","mcp","atlassian","confluence","jira","cve-2026-77257"],"_cs_type":"advisory","_cs_vendors":["sooperset"],"content_html":"\u003cp\u003eThe mcp-atlassian library (prior to version 0.22.0) contains a vulnerability in the \u003ccode\u003evalidate_url_for_ssrf()\u003c/code\u003e function that allows for Server-Side Request Forgery (SSRF). The issue stems from a URL parser mismatch between Python's \u003ccode\u003eurllib.parse.urlparse()\u003c/code\u003e, used for validation, and the downstream \u003ccode\u003erequests.Session\u003c/code\u003e client used to execute requests. By crafting a URL containing a backslash preceding a domain-like string (e.g., \u003ccode\u003ehttp://127.0.0.1:6666\\@www.baidu.com\u003c/code\u003e), an attacker can cause the security validator to evaluate a public domain while the underlying HTTP client resolves the internal host. This vulnerability allows an attacker to bypass SSRF protections and interact with internal-only services or the loopback interface, potentially leading to unauthorized data access or service exploitation.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an endpoint accepting \u003ccode\u003eX-Atlassian-Jira-Url\u003c/code\u003e or \u003ccode\u003eX-Atlassian-Confluence-Url\u003c/code\u003e headers.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious URL containing a backslash to exploit parsing differences between \u003ccode\u003eurllib\u003c/code\u003e and \u003ccode\u003erequests\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker initiates an MCP session with the target application via a \u003ccode\u003ePOST /mcp\u003c/code\u003e request, injecting the malicious URL header.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003evalidate_url_for_ssrf()\u003c/code\u003e function executes, parsing the input and validating the public domain instead of the intended target.\u003c/li\u003e\n\u003cli\u003eThe library's \u003ccode\u003erequests.Session\u003c/code\u003e object receives the URL and interprets it as a connection to the restricted internal or loopback address.\u003c/li\u003e\n\u003cli\u003eThe server performs an outbound request to the sensitive internal host.\u003c/li\u003e\n\u003cli\u003eAttacker receives interaction or response data from the internal service through the application's response handling.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-77274 allows an attacker to bypass intended network access controls, potentially accessing sensitive internal metadata services, administrative interfaces, or local network resources that are otherwise unreachable from the internet. This poses a high risk to environments where the \u003ccode\u003emcp-atlassian\u003c/code\u003e library is used to integrate with Jira or Confluence, as it breaks the isolation layer intended to protect internal service infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the upgrade of the \u003ccode\u003emcp-atlassian\u003c/code\u003e package to version 0.22.0 or later to include the patch for CVE-2026-77274. In environments where patching is delayed, implement strict allowlisting of permissible destination hosts within your proxy or egress firewall rules. Use the log sources identified below to hunt for anomalous \u003ccode\u003eX-Atlassian-Jira-Url\u003c/code\u003e or \u003ccode\u003eX-Atlassian-Confluence-Url\u003c/code\u003e header values that contain backslashes or suspicious loopback IP address formats.\u003c/p\u003e\n","date_modified":"2026-09-23T01:58:02Z","date_published":"2026-09-23T01:57:29Z","id":"https://feed.craftedsignal.io/briefs/2026-09-mcp-atlassian-ssrf/","summary":"The mcp-atlassian library is vulnerable to an SSRF bypass (CVE-2026-77274) due to a URL parsing discrepancy between the security validator and the HTTP client, allowing attackers to access internal or loopback services.","title":"SSRF Protection Bypass in mcp-atlassian","url":"https://feed.craftedsignal.io/briefs/2026-09-mcp-atlassian-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:sooperset:mcp-Atlassian:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}