CVE-2026-55096
Received Received - Intake

SSRF via Unsafe URL Fetching in fast-mcp-telegram

Vulnerability report for CVE-2026-55096, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

fast-mcp-telegram is a Telegram MCP Server. Prior to version 30.1, the send_message/send_message_to_phone MCP tools accept files as a list of http(s) URLs, which the server downloads and attaches to the outgoing Telegram message. Downloads are guarded by _validate_url_security, an SSRF denylist that checks the URL's literal hostname string but never resolves DNS. The fetch (httpx.AsyncClient.get) does its own resolution at request time. Consequently a hostname that resolves to a loopback / private / link-local address passes the guard and is fetched β€” even with the secure defaults block_private_ips=True and allow_http_urls=False. Because the fetched body is returned to the attacker as a Telegram file attachment, this is a full-read, exfiltrating SSRF, not blind. This issue has been patched in version 30.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
fast-mcp-telegram fast-mcp-telegram to 30.1 (exc)
leshchenko1979 fast_mcp_telegram to 0.30.1 (exc)
leshchenko1979 fast_mcp_telegram 30.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
CWE-184 The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-55096 is a Server-Side Request Forgery (SSRF) vulnerability in the fast-mcp-telegram project. It allows authenticated users to bypass security checks by exploiting a DNS-resolution gap. The server downloads files from URLs provided by users but validates the hostname string without resolving DNS first. This lets attackers use hostnames that resolve to internal or loopback addresses (like 127.0.0.1) after passing the initial check. The server then fetches the content and sends it back to the attacker via Telegram file attachments, enabling data exfiltration.

Detection Guidance

To detect this vulnerability, monitor network traffic for unexpected outbound requests to loopback, private, or link-local addresses from the fast-mcp-telegram service. Check logs for Telegram file attachments containing internal data. Use tools like tcpdump or Wireshark to inspect HTTP(S) requests initiated by the service.

Impact Analysis

This vulnerability allows attackers to read internal service responses by tricking the server into fetching URLs pointing to internal or loopback addresses. If you use fast-mcp-telegram, an attacker with access could exfiltrate sensitive data from your internal network via Telegram. The impact includes unauthorized access to internal services and potential data leaks, even if secure defaults like block_private_ips=True are enabled.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA by enabling unauthorized access to sensitive data. GDPR requires protecting personal data, and HIPAA mandates safeguarding protected health information. An SSRF flaw allowing data exfiltration violates these regulations' security requirements, potentially resulting in legal penalties, fines, or reputational damage.

Mitigation Strategies

Immediately upgrade fast-mcp-telegram to version 0.30.1 or later. Disable the send_message/send_message_to_phone tools if not required. Review network firewall rules to block outbound connections to internal or sensitive IP ranges from the service. Monitor for unusual Telegram file attachments.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55096. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart