---
title: "GitLab MCP CVE-2026-61568 - Streamable HTTP DNS Rebinding to Localhost"
description: "CVE-2026-61568 (CVSS 9.6): @zereight/mcp-gitlab Streamable HTTP skipped SDK DNS-rebinding Host/Origin allowlists on loopback - fixed in 2.1.30."
url: "https://anomity.ai/blog/mcp-gitlab-streamable-http-dns-rebinding-cve-2026-61568/"
source: html
---

On this page

- The missing allowlist
- Why REMOTE_AUTHORIZATION is not the fix
- How Anomity governs local GitLab MCP HTTP
- Frequently asked questions

[← Back to blog](https://anomity.ai/blog/)

- Home

- Blog

- GitLab MCP CVE-2026-61568 - Streamable HTTP DNS Rebinding to Localhost

![Anomity robot illustrating GitLab MCP CVE-2026-61568 - Streamable HTTP DNS Rebinding to Localhost]

Advisory Critical

# GitLab MCP CVE-2026-61568 - Streamable HTTP DNS Rebinding to Localhost

Anomity Research
Anomity Threat Research
·
Sep 21, 2026
·
2 min read

Share: Copied

MCP Server Security · Critical · CVE-2026-61568 (CVSS 9.6, GHSA-vmp7-252j-cwp7) · Sep 21, 2026

Affected @zereight/mcp-gitlab before 2.1.30 (Streamable HTTP /mcp without Host/Origin DNS-rebinding controls)

**CVE-2026-61568** (**GHSA-vmp7-252j-cwp7**) hits **@zereight/mcp-gitlab**, a widely used npm MCP server for GitLab. Its **Streamable HTTP** endpoint accepted attacker-controlled **Host** and **Origin** headers because the SDK DNS-rebinding knobs were never enabled. Default bind **127.0.0.1** is exactly what DNS rebinding is for. Fixed in **2.1.30**; GHSA published **15 September 2026**. CVSS **9.6**.

## The missing allowlist

The vulnerable setup created **StreamableHTTPServerTransport** with a session id generator and metrics hooks - and **without** `enableDnsRebindingProtection`, `allowedHosts`, or `allowedOrigins`. Express JSON parsing sat globally before any Host/Origin gate on `/mcp`. A malicious page that rebinds DNS to the victim's loopback can therefore speak MCP to the local listener while preserving attacker-chosen headers.

Once a session initializes, impact depends on credentials already available to the MCP process. With a GitLab token present, tools such as **list_project_variables** can pull **CI/CD secrets**. That is not a theoretical side channel: it is the documented tool surface of a GitLab MCP. Adjacent MCP HTTP failures - [LiteLLM MCP OAuth passthrough](https://anomity.ai/blog/litellm-mcp-oauth-passthrough-auth-bypass-cve-2026-59822/), [AI gateway OAuth passthrough anti-patterns](https://anomity.ai/blog/ai-gateway-oauth-passthrough-mcp/), and [network-ai empty-secret cross-origin MCP](https://anomity.ai/blog/network-ai-empty-secret-cross-origin-mcp-cve-2026-46701/) - rhyme for the same reason: HTTP boundaries on MCP are security-critical, not cosmetic.

## Why REMOTE_AUTHORIZATION is not the fix

The package documents **REMOTE_AUTHORIZATION=true** for multi-user HTTP deployments. In that mode, unauthenticated **tools/list** and material GitLab API calls are blocked by token checks. Useful - and incomplete. The Host/Origin defect remains at the browser boundary: the server still accepts attacker-controlled headers and processes **initialize** instead of rejecting cross-origin localhost access. Authz after a poisoned session start is not the same as refusing the session.

- Upgrade to @zereight/mcp-gitlab 2.1.30+ (PR #555 / commit 52207c6f enables DNS-rebinding protection and restricts allowed hosts/origins).
- Prefer stdio for single-user local agent wiring when Streamable HTTP is unnecessary.
- Assume loopback HTTP MCP is browser-reachable until Host/Origin allowlists are proven on.
- Rotate GitLab tokens and CI variables if a vulnerable listener was active during browser use of untrusted sites.
- Inventory localhost MCP ports across developer endpoints - they rarely appear in vulnerability scanners aimed at prod.

Read alongside [MySQL MCP SSE DNS rebinding CVE-2026-59971](https://anomity.ai/blog/mysql-mcp-server-sse-dns-rebinding-unauth-sql-cve-2026-59971/) and the class analysis of [local MCP HTTP DNS rebinding](https://anomity.ai/blog/mcp-local-http-dns-rebinding-class-2026/). Same SDK features, same forgotten enable flags.

## How Anomity governs local GitLab MCP HTTP

Anomity's **Endpoint Sensor** inventories MCP servers and agents on each managed endpoint so `@zereight/mcp-gitlab` versions and HTTP listeners are visible fleet-wide. **Browser Sensor** and **cloud discovery** cover adjacent AI OAuth surfaces. At the agent hook (for example Claude Code **PreToolUse**), [runtime governance](https://anomity.ai/#runtime-governance) can **deny** sensitive GitLab tool calls before they run, with a [90-day audit trail](https://anomity.ai/#outcomes) to SIEM, Slack, email, or Jira. SOC 2 Type II; complements Network, EDR, DLP, and GRC.

Upgrade to **2.1.30**, treat localhost MCP HTTP as a browser trust boundary, and [request early access](https://anomity.ai/#early-access) to inventory which Streamable HTTP listeners your developers actually left open.

Share: Copied

## Frequently asked questions

Am I affected by CVE-2026-61568?
You are in scope if any endpoint runs @zereight/mcp-gitlab before 2.1.30 with the Streamable HTTP transport enabled. Confirm package version and whether developers pointed agents at a local /mcp HTTP URL rather than stdio-only wiring.

Does REMOTE_AUTHORIZATION mitigate this?
It reduces unauthenticated tools/list and material GitLab API tool calls when tokens are required. It does not reject attacker-controlled Host or Origin headers at the HTTP boundary, so MCP initialize can still succeed via DNS rebinding. Treat auth middleware and Host/Origin allowlists as separate controls.

What is the CVSS vector?
GLAD publishes CVSS 9.6 Critical with CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H. User interaction is present (victim browses an attacker page), but impact remains high confidentiality, integrity, and availability with scope change when GitLab tools and tokens are reachable.

What should teams do first?
Upgrade to 2.1.30 or later everywhere the package is installed. Prefer stdio for local agent use when HTTP is unnecessary. Inventory local MCP HTTP listeners and GitLab tokens on developer machines. Rotate CI variables if a pre-fix Streamable HTTP listener was reachable from a browser session.

How does Anomity help?
Anomity inventories MCP servers and related CLIs on managed endpoints so localhost Streamable HTTP listeners and package versions become visible. Runtime governance can deny sensitive tools/call paths at the agent hook before they run, with a 90-day audit trail to SIEM, Slack, email, or Jira. Metadata only; secrets redacted on-endpoint. Complements Network, EDR, DLP, and GRC.

## Related

[Advisory Critical ### mcp-atlassian HTTP Auth Bypass Falls Back to Global Credentials - CVE-2026-77254 CVE-2026-77254 (CVSS 9.1): unauthenticated HTTP MCP requests to mcp-atlassian below 0.22.0 fall through to globally configured Jira/Confluence credentials. Sibling CVE-2026-77244 (CVSS 10.0) accepts any non-empty token. Anomity Research · Sep 28, 2026 · CVE-2026-77254 (CVSS 9.1, GHSA-vc8m-84rp-53hx); sibling CVE-2026-77244 (CVSS 10.0, GHSA-wrhw-j3f9-8vc6)](https://anomity.ai/blog/mcp-atlassian-http-auth-bypass-global-credentials-cve-2026-77254/)

[Advisory Critical ### MySQL MCP Server CVE-2026-59971 - Unauthenticated SQL via SSE DNS Rebinding CVE-2026-59971 (CVSS 10.0): mysql-mcp-server SSE mode skipped Host/Origin DNS-rebinding protection, bound 0.0.0.0 with no auth - unauthenticated SQL until 0.4.2. Anomity Research · Sep 21, 2026 · CVE-2026-59971 (CVSS 10.0, GHSA-rqfv-2mw9-78g2)](https://anomity.ai/blog/mysql-mcp-server-sse-dns-rebinding-unauth-sql-cve-2026-59971/)

[Advisory High ### LiteLLM MCP Auth Bypass CVE-2026-59822 Lands in CISA KEV CVE-2026-59822 (CVSS 8.2, GHSA-7488-6r32-c95q): LiteLLM MCP Streamable HTTP OAuth2 passthrough yielded empty UserAPIKeyAuth. Fixed in 1.84.0; CISA KEV deadline 2026-09-16. Anomity Research · Sep 14, 2026 · CVE-2026-59822 (CVSS 8.2, GHSA-7488-6r32-c95q)](https://anomity.ai/blog/litellm-mcp-oauth-passthrough-auth-bypass-cve-2026-59822/)

## Structured data

```json
{
  "@context": "https://schema.org",
  "@type": "TechArticle",
  "headline": "GitLab MCP CVE-2026-61568 - Streamable HTTP DNS Rebinding to Localhost",
  "description": "CVE-2026-61568 (CVSS 9.6): @zereight/mcp-gitlab Streamable HTTP skipped SDK DNS-rebinding Host/Origin allowlists on loopback - fixed in 2.1.30.",
  "datePublished": "2026-09-21",
  "dateModified": "2026-09-21",
  "author": {
    "@type": "Organization",
    "name": "Anomity",
    "url": "https://anomity.ai/",
    "sameAs": [
      "https://www.linkedin.com/company/anomity",
      "https://github.com/Anomity-ai",
      "https://www.wikidata.org/wiki/Q140763940"
    ]
  },
  "publisher": {
    "@type": "Organization",
    "name": "Anomity",
    "url": "https://anomity.ai/",
    "sameAs": [
      "https://www.linkedin.com/company/anomity",
      "https://github.com/Anomity-ai",
      "https://www.wikidata.org/wiki/Q140763940"
    ],
    "logo": {
      "@type": "ImageObject",
      "url": "https://anomity.ai/icon-512.png"
    }
  },
  "mainEntityOfPage": {
    "@type": "WebPage",
    "@id": "https://anomity.ai/blog/mcp-gitlab-streamable-http-dns-rebinding-cve-2026-61568/"
  },
  "image": {
    "@type": "ImageObject",
    "url": "https://anomity.ai/assets/blog/covers/prompt-injection.jpg",
    "width": 1200,
    "height": 630
  },
  "articleSection": "MCP Server Security",
  "url": "https://anomity.ai/blog/mcp-gitlab-streamable-http-dns-rebinding-cve-2026-61568/",
  "keywords": "GitLab MCP CVE-2026-61568 DNS rebinding, CVE-2026-61568 (CVSS 9.6, GHSA-vmp7-252j-cwp7), CVE-2026-61568, GHSA-vmp7-252j-cwp7, @zereight/mcp-gitlab, GitLab MCP, Streamable HTTP, DNS rebinding, localhost MCP, CI secrets, agentic AI security"
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "Am I affected by CVE-2026-61568?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "You are in scope if any endpoint runs @zereight/mcp-gitlab before 2.1.30 with the Streamable HTTP transport enabled. Confirm package version and whether developers pointed agents at a local /mcp HTTP URL rather than stdio-only wiring."
      }
    },
    {
      "@type": "Question",
      "name": "Does REMOTE_AUTHORIZATION mitigate this?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "It reduces unauthenticated tools/list and material GitLab API tool calls when tokens are required. It does not reject attacker-controlled Host or Origin headers at the HTTP boundary, so MCP initialize can still succeed via DNS rebinding. Treat auth middleware and Host/Origin allowlists as separate controls."
      }
    },
    {
      "@type": "Question",
      "name": "What is the CVSS vector?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "GLAD publishes CVSS 9.6 Critical with CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H. User interaction is present (victim browses an attacker page), but impact remains high confidentiality, integrity, and availability with scope change when GitLab tools and tokens are reachable."
      }
    },
    {
      "@type": "Question",
      "name": "What should teams do first?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Upgrade to 2.1.30 or later everywhere the package is installed. Prefer stdio for local agent use when HTTP is unnecessary. Inventory local MCP HTTP listeners and GitLab tokens on developer machines. Rotate CI variables if a pre-fix Streamable HTTP listener was reachable from a browser session."
      }
    },
    {
      "@type": "Question",
      "name": "How does Anomity help?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Anomity inventories MCP servers and related CLIs on managed endpoints so localhost Streamable HTTP listeners and package versions become visible. Runtime governance can deny sensitive tools/call paths at the agent hook before they run, with a 90-day audit trail to SIEM, Slack, email, or Jira. Metadata only; secrets redacted on-endpoint. Complements Network, EDR, DLP, and GRC."
      }
    }
  ]
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "BreadcrumbList",
  "itemListElement": [
    {
      "@type": "ListItem",
      "position": 1,
      "name": "Home",
      "item": "https://anomity.ai/"
    },
    {
      "@type": "ListItem",
      "position": 2,
      "name": "Blog",
      "item": "https://anomity.ai/blog/"
    },
    {
      "@type": "ListItem",
      "position": 3,
      "name": "GitLab MCP CVE-2026-61568 - Streamable HTTP DNS Rebinding to Localhost",
      "item": "https://anomity.ai/blog/mcp-gitlab-streamable-http-dns-rebinding-cve-2026-61568/"
    }
  ]
}
```
