Skip to content

fix(server): require a numeric port for Host/Origin :* allowlist entries - #3465

Closed
Oskii wants to merge 1 commit into
modelcontextprotocol:mainfrom
Oskii:fix/dns-rebinding-wildcard-port
Closed

fix(server): require a numeric port for Host/Origin :* allowlist entries#3465
Oskii wants to merge 1 commit into
modelcontextprotocol:mainfrom
Oskii:fix/dns-rebinding-wildcard-port

Conversation

@Oskii

@Oskii Oskii commented Sep 6, 2026

Copy link
Copy Markdown

Fixes #3463

What

HTTP transports can enable DNS rebinding protection with allowed_hosts / allowed_origins. An entry that ends in :* is meant to allow any port on that host or origin.

The matcher was a prefix check:

if host.startswith(base_host + ":"):
    return True

So allowed_hosts=["wild.example:*"] also accepted wild.example:9000.evil. The same form accepted Origin http://wild.example:9000.evil for http://wild.example:*.

Existing tests only used a numeric port (wild.example:9000). After the fix, the suffix after base: must be digits. wild.example:9000 still passes. wild.example:9000.evil and an empty port do not.

Why

I was reading TransportSecurityMiddleware next to tests/server/test_transport_security.py. The wildcard cases only cover wild.example:9000. I tried a Host that starts with that prefix and keeps going (wild.example:9000.evil) and validate_request returned None.

This matters when someone turns protection on and trusts :* to mean "this host, any port". A client that can set Host or Origin can satisfy the allowlist with a longer value.

How

Share one helper: base:* matches only base:<digits>. Host and Origin both use it. No new settings.

Testing

Added host-wildcard-suffix-rejected, host-wildcard-empty-port, and origin-wildcard-suffix-rejected to test_validate_request_checks_host_then_origin.

uv run pytest tests/server/test_transport_security.py -q

29 passed.

Written with AI assistance. I read the matcher, reproduced the suffix case, and kept the existing numeric-port tests.

The wildcard matcher used startswith(base + ":"), so wild.example:9000.evil
was accepted for wild.example:*. Require the suffix to be digits.

Fixes modelcontextprotocol#3463
@github-actions github-actions Bot added the missing-issue-link Auto-closed: PR needs a linked issue assigned to its author (see CONTRIBUTING.md) label Sep 6, 2026
@github-actions

github-actions Bot commented Sep 6, 2026

Copy link
Copy Markdown
Contributor

This PR has been closed automatically. This repo only keeps pull requests open when they come from a maintainer, or from a contributor a maintainer has assigned to the linked issue, and you aren't currently assigned to #3463.

If a maintainer assigns you to #3463, this PR reopens on its own and there's nothing more you need to do here. Assignment is a maintainer call based on capacity; comments that only ask to be assigned don't factor in. What does help is engaging on the issue itself by confirming the repro, explaining why it matters for your use case, or describing the approach you'd take.

You're welcome to keep pushing commits here (just avoid force-pushing, since GitHub can't reopen a rewritten branch), but that on its own won't get the PR reviewed or the issue assigned, and realistically most auto-closed PRs stay closed. There's no need to open a new PR either way.

CONTRIBUTING.md has the full reasoning, but in short:

  • We're a small team with very little capacity to review community PRs right now.
  • Many recent PRs are AI-generated with little human review, and reviewing one carefully still costs a maintainer as much time as it ever did. A well-described issue is usually more useful to us than the code.

Maintainers: reopen, remove missing-issue-link, or add bypass-issue-check to override.

@github-actions github-actions Bot closed this Sep 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

missing-issue-link Auto-closed: PR needs a linked issue assigned to its author (see CONTRIBUTING.md)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

DNS rebinding :* allowlist matches Host/Origin suffixes that are not ports

1 participant