Get a demo — 30 minutes →
← Back to blog
Anomity robot illustrating MySQL MCP Server CVE-2026-59971 - Unauthenticated SQL via SSE DNS Rebinding
AdvisoryCritical

MySQL MCP Server CVE-2026-59971 - Unauthenticated SQL via SSE DNS Rebinding

MCP Server Security·Critical·CVE-2026-59971 (CVSS 10.0, GHSA-rqfv-2mw9-78g2)·
Affected mysql-mcp-server (PyPI) before 0.4.2 when MCP_TRANSPORT=sse; default stdio transport is not affected

CVE-2026-59971 (GHSA-rqfv-2mw9-78g2) is a critical flaw in mysql-mcp-server, the popular PyPI MCP package that fronted MySQL for coding agents. In SSE/HTTP mode the server skipped the SDK's Host/Origin DNS-rebinding guards, listened broadly, and required no authentication - so unauthenticated callers could drive SQL. Fixed in 0.4.2; GHSA published 11 September 2026. CVSS 10.0.

What broke

Trigger condition: MCP_TRANSPORT=sse. In that mode the package constructed SseServerTransport without passing security_settings. The MCP Python SDK's DNS-rebinding protection - Origin and Host validation - therefore stayed disabled. The Starlette app also lacked CORS and TrustedHost middleware, bound 0.0.0.0 by default, and exposed routes without authentication.

That combination is the classic local-MCP HTTP failure mode: developers assume "it is just on my laptop," while the browser origin boundary and the network bind disagree. DNS rebinding lets a malicious page reach a listener the developer thought was private; a directly exposed host needs no rebinding at all. Either path yields unauthenticated SQL against whatever database credentials the MCP process holds. Coding-agent servers share the assumption; OpenCode's cross-site upgrade flaw reached a local server through a form post instead.

Default stdio is not affected. The CVE is specifically about the HTTP/SSE code path - the same transport class covered in broader Model Context Protocol security guidance and in sibling unauthenticated MCP takes such as Windows MCP unauthenticated PowerShell RCE and Weknora unauthenticated MCP RCE.

Fix and residual risk

  • Upgrade to mysql-mcp-server 0.4.2 or later - the fixed release restores DNS-rebinding protection and related host allowlisting.
  • Do not run SSE unless you need it - prefer stdio for local agent wiring when HTTP is not required.
  • Bind loopback and front with an authenticated reverse proxy if SSE must stay on; the advisory class still warns that transport alone is not a full auth story.
  • Least-privilege MySQL credentials for the MCP process so a remaining misconfig cannot dump production schemas.
  • Inventory who enabled MCP_TRANSPORT=sse - environment flags on developer machines rarely appear in a CMDB.

This finding pairs with the same week's GitLab MCP streamable HTTP DNS rebinding and the pattern write-up on why local MCP HTTP keeps falling to DNS rebinding. SDK knobs exist; package authors keep shipping without enabling them.

How Anomity surfaces exposed MCP HTTP

Patching 0.4.2 closes this CVE. The durable control is still knowing which MCP URLs and transports run where, and denying unsafe tool calls before they execute.

Anomity's Endpoint Sensor inventories MCP servers among the eight AI artifact types on each managed endpoint, so an unexpected SSE listener is a fleet query. Browser Sensor and cloud discovery (Google Workspace / GitHub OAuth grants) cover adjacent AI surfaces. On agents with a hook such as Claude Code PreToolUse, runtime governance returns allow, deny, or log before a call runs. Every decision lands in a queryable 90-day audit trail and can route to SIEM, Slack, email, or Jira. Anomity is SOC 2 Type II and complements Network, EDR, DLP, and GRC.

CVE-2026-59971 is what happens when MCP HTTP is treated as a convenience flag. Upgrade to 0.4.2, inventory SSE listeners, and book a 30-minute demo to see which MCP transports your fleet actually exposed.

Frequently asked questions

Am I affected by CVE-2026-59971?

You are in scope if any host runs the PyPI package mysql-mcp-server before 0.4.2 with MCP_TRANSPORT=sse. Stdio-only deployments of the same package are outside this CVE. Confirm the installed version on developer and server endpoints, and whether SSE was enabled via environment or config rather than assumed from the README default.

What failed in the SSE transport?

SseServerTransport was created without security_settings, which disabled the MCP Python SDK Origin and Host checks that exist specifically to stop DNS rebinding. Combined with a default bind to 0.0.0.0, missing CORS/TrustedHost middleware, and no route authentication, a browser-origin or network attacker who can reach the listener can drive MCP traffic - including SQL-capable tools - without credentials.

Why is CVSS 10.0 for a local MCP package?

The published vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Network-reachable, unauthenticated SQL against a production database is a full confidentiality, integrity, and availability hit with scope change. Loopback-only mental models do not apply when the process binds all interfaces and skips Host/Origin validation.

Is upgrading to 0.4.2 enough?

It is the required fix for this CVE: 0.4.2 turns DNS-rebinding protection back on and documents MCP_SSE_ALLOWED_HOSTS. SSE still needs deployment hygiene - prefer loopback bind, authenticated reverse proxy, and least-privilege MySQL credentials - because transport hardening is not the same as application authentication for every exposure model.

How does Anomity help with exposed MCP HTTP listeners?

Anomity's Endpoint Sensor inventories MCP servers among the AI artifacts on each managed endpoint, so SSE and HTTP listeners become a fleet query rather than a rumor. On agents that expose a hook such as Claude Code PreToolUse, Anomity returns allow, deny, or log before a tools/call runs. Decisions land in a queryable 90-day audit trail and can route to SIEM, Slack, email, or Jira. Metadata only; secrets are redacted on-endpoint. That complements Network, EDR, DLP, and GRC.

Ask AI about Anomity
ChatGPT Claude Perplexity Google AI Grok