CyberRota
← Ana sayfaya dön

CVE-2026-16328

HIGH · CVSS 8.6

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-07-29T19:16:45.060 · Çekilme zamanı: 2026-07-30T00:07:45.625481+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-16328
Severity
HIGH
CVSS
8.6
EPSS
Yok

Orijinal NVD Açıklaması

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to override the server's configured Consul address via a request header. This may allow a malicious client to redirect the server's Consul API traffic to an attacker-controlled endpoint, potentially exfiltrating the Consul token configured on the server. This vulnerability, CVE-2026-16328, is fixed in consul-mcp-server 0.1.4.