RHSA-2026:62537MediumCVSS 6.8
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-81092 — github.com/mark3labs/mcp-go: mcp-go: DNS Rebinding vulnerability due to missing Host header validation
🎯 Affected products4
- Red Hat Hardened Images
- tempo3-0-main@aarch64 as a component of Red Hat Hardened Images
- tempo3-0-main@src as a component of Red Hat Hardened Images
- tempo3-0-main@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Where an immediate update to mcp-go v0.56.0 is not possible: restrict inbound connections to known trusted clients via network policy or firewall rules, and place a reverse proxy in front of the MCP endpoint that enforces strict Host header validation.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:62537
- externalhttps://access.redhat.com/security/cve/CVE-2026-81092
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://images.redhat.com/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_62537.json