Skip to content

Add advisory for dynoxide-rs (DNS rebinding / CSRF)#2852

Merged
djc merged 2 commits into
rustsec:mainfrom
hicksy:main
May 13, 2026
Merged

Add advisory for dynoxide-rs (DNS rebinding / CSRF)#2852
djc merged 2 commits into
rustsec:mainfrom
hicksy:main

Conversation

@hicksy
Copy link
Copy Markdown

@hicksy hicksy commented May 12, 2026

Filing the dynoxide-rs counterpart to GHSA-fvh2-gm75-j4j7 / CVE-2026-42559 so cargo audit and cargo deny users get the alert.

The vulnerability lives in the MCP HTTP transport. dynoxide 0.9.13 ships the fix. Full write-up in the GHSA.

Comment thread crates/dynoxide-rs/RUSTSEC-0000-0000.md Outdated
Comment on lines +36 to +38
- GitHub Security Advisory: https://github.com/nubo-db/dynoxide/security/advisories/GHSA-fvh2-gm75-j4j7
- Upstream rmcp advisory: https://github.com/modelcontextprotocol/rust-sdk/security/advisories/GHSA-89vp-x53w-74fx
- dynoxide release: https://github.com/nubo-db/dynoxide/releases/tag/v0.9.13 No newline at end of file
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's keep these in the metadata, and not repeat them here. (There's already an alias for the GHSA, so no need to repeat it as a reference.)

I notice there has not been a RustSec advisory for the rmcp problem, maybe you can work with them to get advisories published?

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done, thanks.
Good point on the rmcp side. I'll reach out to the maintainers and see if they'd like an advisory published.

@djc
Copy link
Copy Markdown
Member

djc commented May 13, 2026

Thanks!

@djc djc merged commit fbe632f into rustsec:main May 13, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants