Threat Advisory

rmcp Flaw Reveals Authentication Credentials Upon Untrusted Host Transfer

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-64684 with a CVSS score of 6.8 is a vulnerability in the rmcp crate where the StreamableHttpClientTransport forwards custom HTTP headers to cross-origin redirect targets because automatic redirect handling does not remove headers configured through custom_headers. An attacker who controls or compromises the original MCP server can issue a 307 or 308 redirect to an attacker-controlled server and capture sensitive headers such as X-API-Key or X-Auth-Token potentially enabling unauthorized access to the MCP server. The vulnerability is addressed by disabling automatic redirect following so redirects can be handled with appropriate header protection.

RECOMMENDATIONS:

  • We recommend you to update rmcp to below version:
  • https://github.com/modelcontextprotocol/rust-sdk/releases

REFERENCES:

The following reports contain further technical details:[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-64684 with a CVSS score of 6.8 is a vulnerability in the rmcp crate where the StreamableHttpClientTransport forwards custom HTTP headers to cross-origin redirect targets because automatic redirect handling does not remove headers configured through custom_headers. An attacker who controls or compromises the original MCP server can issue a 307 or 308 redirect to an attacker-controlled server and capture sensitive headers such as X-API-Key or X-Auth-Token potentially enabling unauthorized access to the MCP server. The vulnerability is addressed by disabling automatic redirect following so redirects can be handled with appropriate header protection.

RECOMMENDATIONS:

  • We recommend you to update rmcp to below version:
  • https://github.com/modelcontextprotocol/rust-sdk/releases

REFERENCES:

The following reports contain further technical details:[emaillocker id="1283"]

[/emaillocker]
crossmenu