CVE-2026-55096: CWE-184: Incomplete List of Disallowed Inputs in leshchenko1979 fast-mcp-telegram
fast-mcp-telegram is a Telegram MCP Server. Prior to version 30.1, the send_message/send_message_to_phone MCP tools accept files as a list of http(s) URLs, which the server downloads and attaches to the outgoing Telegram message. Downloads are guarded by _validate_url_security, an SSRF denylist that checks the URL's literal hostname string but never resolves DNS. The fetch (httpx.AsyncClient.get) does its own resolution at request time. Consequently a hostname that resolves to a loopback / private / link-local address passes the guard and is fetched — even with the secure defaults block_private_ips=True and allow_http_urls=False. Because the fetched body is returned to the attacker as a Telegram file attachment, this is a full-read, exfiltrating SSRF, not blind. This issue has been patched in version 30.1.
AI Analysis
Technical Summary
The vulnerability in fast-mcp-telegram (CVE-2026-55096) arises because the _validate_url_security function only checks the literal hostname string against a denylist and does not perform DNS resolution. Meanwhile, the HTTP client used to fetch URLs resolves DNS at request time. This discrepancy allows an attacker to supply URLs that appear safe by hostname but resolve to loopback, private, or link-local IP addresses, bypassing the SSRF protections. The server then fetches these internal resources and attaches the response body to outgoing Telegram messages, enabling full data exfiltration. The vulnerability affects versions prior to 30.1 and has been patched in 30.1.
Potential Impact
An attacker with at least low privileges can exploit this SSRF vulnerability to cause the server to fetch internal network resources that should be inaccessible externally. Because the fetched content is returned as a Telegram file attachment, the attacker can fully read and exfiltrate sensitive internal data. The vulnerability impacts confidentiality (high impact), with limited integrity impact and no availability impact. There are no known exploits in the wild as of the publication date.
Mitigation Recommendations
This vulnerability is fixed in fast-mcp-telegram version 30.1. Users should upgrade to version 30.1 or later to remediate this issue. No additional mitigation steps are required once the upgrade is applied.
CVE-2026-55096: CWE-184: Incomplete List of Disallowed Inputs in leshchenko1979 fast-mcp-telegram
Description
fast-mcp-telegram is a Telegram MCP Server. Prior to version 30.1, the send_message/send_message_to_phone MCP tools accept files as a list of http(s) URLs, which the server downloads and attaches to the outgoing Telegram message. Downloads are guarded by _validate_url_security, an SSRF denylist that checks the URL's literal hostname string but never resolves DNS. The fetch (httpx.AsyncClient.get) does its own resolution at request time. Consequently a hostname that resolves to a loopback / private / link-local address passes the guard and is fetched — even with the secure defaults block_private_ips=True and allow_http_urls=False. Because the fetched body is returned to the attacker as a Telegram file attachment, this is a full-read, exfiltrating SSRF, not blind. This issue has been patched in version 30.1.
CVSS v3.1
Score 7.1high
Affected software
leshchenko1979
fast-mcp-telegram
pkg:github/leshchenko1979/fast-mcp-telegramRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in fast-mcp-telegram (CVE-2026-55096) arises because the _validate_url_security function only checks the literal hostname string against a denylist and does not perform DNS resolution. Meanwhile, the HTTP client used to fetch URLs resolves DNS at request time. This discrepancy allows an attacker to supply URLs that appear safe by hostname but resolve to loopback, private, or link-local IP addresses, bypassing the SSRF protections. The server then fetches these internal resources and attaches the response body to outgoing Telegram messages, enabling full data exfiltration. The vulnerability affects versions prior to 30.1 and has been patched in 30.1.
Potential Impact
An attacker with at least low privileges can exploit this SSRF vulnerability to cause the server to fetch internal network resources that should be inaccessible externally. Because the fetched content is returned as a Telegram file attachment, the attacker can fully read and exfiltrate sensitive internal data. The vulnerability impacts confidentiality (high impact), with limited integrity impact and no availability impact. There are no known exploits in the wild as of the publication date.
Mitigation Recommendations
This vulnerability is fixed in fast-mcp-telegram version 30.1. Users should upgrade to version 30.1 or later to remediate this issue. No additional mitigation steps are required once the upgrade is applied.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-16T14:41:54.578Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aba9de2f7a7c54106f66c91
Added to database: 09/28/2026, 17:03:30 UTC
Last enriched: 09/28/2026, 17:17:45 UTC
Last updated: 09/29/2026, 02:50:29 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.