PT-2026-94090 · Crates.Io · Rmcp
CVE-2026-64684
·
Published
2026-09-16
·
Updated
2026-09-23
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
rmcp versions prior to 2.1.0
Description
The
StreamableHttpClientTransport in the rmcp crate fails to mark caller-supplied custom HTTP headers as sensitive and uses a default HTTP client with an automatic redirect policy. When a compromised or malicious MCP endpoint returns a cross-origin 307 or 308 redirect, the client follows the redirect and forwards the custom headers to the new origin. This allows an attacker to capture and reuse sensitive information, such as API keys or authentication tokens, provided via the StreamableHttpClientTransportConfig.custom headers variable. The issue occurs within the default http client() and apply custom headers() functions. The auth header path is not affected as it uses the standard Authorization header, which is automatically stripped during cross-origin redirects.Recommendations
Update to version 2.1.0.
As a temporary mitigation, avoid using the
custom headers variable in StreamableHttpClientTransportConfig to store sensitive authentication tokens until the update is applied.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rmcp