Skip to content

MCPA-2026-0028

highssrfCVSS 8.2

mcp-atlassian unauthenticated SSRF via X-Atlassian-*-Url headers (CVE-2026-27826)

mcp-atlassian (PyPI) before 0.17.0 lets an unauthenticated attacker who can reach the HTTP endpoint force the server to make outbound HTTP requests to an arbitrary attacker-controlled URL by supplying the custom X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers without an Authorization header. Fixed in 0.17.0 by validating the header-supplied URLs.

Affected packages

EcosystemPackageAffected versions
pypimcp-atlassian
>= 0, < 0.17.0

Identifiers

CVE-2026-27826GHSA-7r34-79r5-rcc9CWE-918

References

Timeline

  • Published: 2026-03-10

← All advisories