CVE Explorer
CVE-2025-64443
MCP Gateway allows easy and secure running and deployment of MCP servers. In versions 0.27.0 and earlier, when MCP Gateway runs in sse or streaming transport mode, it is vulnerable to DNS rebinding. An attacker who can get a victim to visit a malicious website or be served a malicious advertisement can perform browser-based exploitation of MCP servers executing behind the gateway, including manipulating tools or other features exposed by those MCP servers. MCP Gateway is not affected when runnin
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"mcp-gateway","vendor":"docker","versions":[{"status":"affected","version":"< 0.28.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:3252211e8e60a3f981e11e209e0a7e2a811702804dca4f4c322361165ececd13 · sha256:3f7616753187c22d… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":7.3,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"PASSIVE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:H/VA:N/SC:H/SI:H/SA:H","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:3252211e8e60a3f981e11e209e0a7e2a811702804dca4f4c322361165ececd13 · sha256:3f7616753187c22d… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-749","description":"CWE-749: Exposed Dangerous Method or Function","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:3252211e8e60a3f981e11e209e0a7e2a811702804dca4f4c322361165ececd13 · sha256:3f7616753187c22d… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/docker/mcp-gateway/commit/6b076b2479d8d1345c50c112119c62978d46858e","tags":["x_refsource_MISC"],"url":"https://github.com/docker/mcp-gateway/commit/6b076b2479d8d1345c50c112119c62978d46858e"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3252211e8e60a3f981e11e209e0a7e2a811702804dca4f4c322361165ececd13 · sha256:3f7616753187c22d… · /containers/cna/references/1
{"name":"https://github.com/docker/mcp-gateway/security/advisories/GHSA-46gc-mwh4-cc5r","tags":["x_refsource_CONFIRM"],"url":"https://github.com/docker/mcp-gateway/security/advisories/GHSA-46gc-mwh4-cc5r"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3252211e8e60a3f981e11e209e0a7e2a811702804dca4f4c322361165ececd13 · sha256:3f7616753187c22d… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.