Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Guilngou

#42026of 57,427
7.1Total CVSS
Vulnerabilities · 1
PT-2026-99930
7.1
2026-09-28
Unknown · Fast-Mcp-Telegram · CVE-2026-55096
**Name of the Vulnerable Software and Affected Versions** fast-mcp-telegram versions prior to 30.1 **Description** The server is subject to a full-read, exfiltrating Server-Side Request Forgery (SSRF), a condition where an attacker can force the server to make requests to internal resources. The `send message` and `send message to phone` MCP tools accept files as a list of http(s) URLs, which the server downloads and attaches to outgoing messages. While the ` validate url security` function implements a denylist to check the literal hostname string, it does not resolve DNS. Since the actual fetch performed by `httpx.AsyncClient.get` resolves DNS at request time, a hostname resolving to a loopback, private, or link-local address can bypass the security guard. This allows an attacker to retrieve the body of the internal request as a Telegram file attachment, even when `block private ips=True` and `allow http urls=False` are configured. **Recommendations** Update to version 30.1.