Known CVE
mcp-atlassian < 0.17.0 - Server-Side Request Forgery
MCP Atlassian < 0.17.0 contains a server-side request forgery caused by improper validation of custom HTTP headers in the HTTP middleware, letting unauthenticated attackers force outbound requests to arbitrary URLs, exploit requires access to the mcp-atlassian HTTP endpoint.
CVE-2026-27826
High2026CVSS 8.2CWE-918
cve2026 · mcp · atlassian · ssrf · oast
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website