Server takeover via DNS rebinding
Published Jun 13, 2026 · Updated Jun 13, 2026
Origin validation errors in Google MCP Toolbox for Databases before 0.25.0 allow remote attackers to control local servers via DNS rebinding. Streamable HTTP handling accepted arbitrary Origin and Host values because server startup provided no host allowlist for rejecting rebinding requests. A victim must load attacker-controlled web content; successful requests can invoke configured tools to read or write connected data and exercise other exposed functions.
Summary
What happened
Origin validation errors in Google MCP Toolbox for Databases before 0.25.0 allow remote attackers to control local servers via DNS rebinding. Streamable HTTP handling accepted arbitrary Origin and Host values because server startup provided no host allowlist for rejecting rebinding requests. A victim must load attacker-controlled web content; successful requests can invoke configured tools to read or write connected data and exercise other exposed functions.
The record
- CVE
- CVE-2026-11624
- Published
- Jun 13, 2026
- Updated
- Jun 13, 2026
- Vendor
- Go standard library
- Product
- MCP Toolbox for Databases
- Classifications
- CWE-346, T1189
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Jun 13, 2026CVE publishedPublication date reported by the CVE source.
- Jun 13, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=0 <0.25.0
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Public exploit references
- Browser DNS-rebinding proof of conceptfunctional · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo