MCPA-2026-0028
highssrfCVSS 8.2
mcp-atlassian unauthenticated SSRF via X-Atlassian-*-Url headers (CVE-2026-27826)
mcp-atlassian (PyPI) before 0.17.0 lets an unauthenticated attacker who can reach the HTTP endpoint force the server to make outbound HTTP requests to an arbitrary attacker-controlled URL by supplying the custom X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers without an Authorization header. Fixed in 0.17.0 by validating the header-supplied URLs.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| pypi | mcp-atlassian | >= 0, < 0.17.0 |
Identifiers
CVE-2026-27826GHSA-7r34-79r5-rcc9CWE-918
References
- advisory https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-7r34-79r5-rcc9
- fix https://github.com/sooperset/mcp-atlassian/commit/5cd697dfce9116ef330b8dc7a91291640e0528d9
- web https://github.com/advisories/GHSA-7r34-79r5-rcc9
Timeline
- Published: 2026-03-10