Unknown · Mcp-Attlasian · CVE-2026-77242
**Name of the Vulnerable Software and Affected Versions**
MCP Atlassian versions prior to 0.22.0
**Description**
The software is susceptible to Server-Side Request Forgery (SSRF), a condition where an attacker can induce the server to make requests to an unintended location. The `validate url for ssrf` function checks a hostname's resolved addresses, but the Requests and urllib3 libraries resolve the hostname again during the connection phase. An attacker can exploit this by using a short-lived DNS answer that appears public during validation but resolves to a private address during the actual connection, allowing unauthenticated access to internal or metadata endpoints. The processing flow involves the `validate url for ssrf`, ` check dns resolution`, `socket.getaddrinfo`, and ` make ssrf safe hook` functions.
**Recommendations**
Update to version 0.22.0.