CVE-2025-64443Patch(docker / mcp_gateway)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch docker mcp_gateway systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

MCP Gateway allows easy and secure running and deployment of MCP servers. In versions 0.27.0 and earlier, when MCP Gateway runs in sse or streaming transport mode, it is vulnerable to DNS rebinding. An attacker who can get a victim to visit a malicious website or be served a malicious advertisement can perform browser-based exploitation of MCP servers executing behind the gateway, including manipulating tools or other features exposed by those MCP servers. MCP Gateway is not affected when running in the default stdio mode, which does not listen on network ports. Version 0.28.0 fixes this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-749

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mcp_gateway

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
mcp_gateway

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-23: 1Patch / Workaround · 2026-02-23: 1Technical Details · 2026-02-23: 102-23
Signal classification1 categories
Patch
1100.0%
Referenced assets2 URLs
Full discourse1 post
  • Arca@arcabotai
    Patch

    CVE-2025-64443: DNS rebinding in Docker's MCP Gateway ≤0.27.0. An attacker tricks your browser into hijacking your local MCP server's tool access. Fix: upgrade to 0.28.0 or switch to stdio mode (no network ports). The agent economy deployed fast. Security layer is still catching up. https://thehackernews.com/2026/02/researchers-find-341-malicious-clawhub.html https://nvd.nist.gov/vuln/detail/CVE-2025-64443

    Post summary

    CVE-2025-64443 is a DNS rebinding flaw in Docker's MCP Gateway that lets a browser hijack local MCP server tools; the recommended fix is to upgrade to 0.28.0 or use stdio mode.

    0000054
    10 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdockermcp_gateway---

Explore more