CVE-2025-64443
Docker MCP Plugin and Docker MCP Gateway have DNS Rebinding vulnerability when running in sse or streaming mode in github.com/docker/mcp-gateway
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/docker/mcp-gateway/security/advisories/GHSA-46gc-mwh4-cc5r, https://nvd.nist.gov/vuln/detail/CVE-2025-64443, https://github.com/docker/mcp-gateway/commit/6b076b2479d8d1345c50c112119c62978d46858e, https://github.com/docker/mcp-gateway/commit/fe073985c8eb6e0c9317d2f198c07686f70ea06d, https://github.com/docker/mcp-gateway/pull/190, https://modelcontextprotocol.io/specification/2025-06-18/basic/transports#security-warning
