PT-2026-94090 · Crates.Io · Rmcp

CVE-2026-64684

·

Published

2026-09-16

·

Updated

2026-09-23

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions rmcp versions prior to 2.1.0
Description The StreamableHttpClientTransport in the rmcp crate fails to mark caller-supplied custom HTTP headers as sensitive and uses a default HTTP client with an automatic redirect policy. When a compromised or malicious MCP endpoint returns a cross-origin 307 or 308 redirect, the client follows the redirect and forwards the custom headers to the new origin. This allows an attacker to capture and reuse sensitive information, such as API keys or authentication tokens, provided via the StreamableHttpClientTransportConfig.custom headers variable. The issue occurs within the default http client() and apply custom headers() functions. The auth header path is not affected as it uses the standard Authorization header, which is automatically stripped during cross-origin redirects.
Recommendations Update to version 2.1.0. As a temporary mitigation, avoid using the custom headers variable in StreamableHttpClientTransportConfig to store sensitive authentication tokens until the update is applied.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64684
GHSA-9G45-5XWM-F3WC
OPENSUSE-SU-2026:11849-1

Affected Products

Rmcp