Skip to content

Known CVE

mcp-atlassian < 0.17.0 - Server-Side Request Forgery

MCP Atlassian < 0.17.0 contains a server-side request forgery caused by improper validation of custom HTTP headers in the HTTP middleware, letting unauthenticated attackers force outbound requests to arbitrary URLs, exploit requires access to the mcp-atlassian HTTP endpoint.

CVE-2026-27826

High2026CVSS 8.2CWE-918

cve2026 · mcp · atlassian · ssrf · oast

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website