hackwither_

reap / rules / auth and session posture

MCP accepted initialize with a mismatched Host header

mcp-host-header-validation ASI03 Identity and Privilege Abuse severity: medium (high on loopback)

What it detects

Server doesn't validate Host during initialize (DNS rebinding exposure). ASI03. Severity is conditional: Medium by default, High only for loopback targets, where a browser-driven rebinding attack reaches a local agent directly — see the calibration note in docs/ASI_MAPPING.md.

Sends initialize with a mismatched Host header; flags servers that process it anyway (no host-name validation). Conditional severity: see docs/ASI_MAPPING.md calibration note.

applies to MCP endpoints

Why it matters

DNS rebinding lets a web page reach an agent endpoint and act with the victim's network position.

OWASP ASI mapping rationale

Example finding

HIGH  mcp-host-header-validation  HIGH CONFIDENCE
MCP accepted initialize with a mismatched Host header
The server processed an initialize request even though the Host header was set to "host-header-validation.invalid", so it does not validate the requested host name before handling MCP traffic. This is the condition DNS-rebinding protection prevents; it is rated high only for loopback endpoints, where a browser-driven rebinding attack reaches a local agent directly.
Evidence  POST /mcp → 200

from a scan of reap-range, bad target

Fix

Validate the Host header or equivalent request target before accepting MCP requests, and refuse requests whose host name does not match the configured endpoint.

On reap-range

insecure targetbad/mcp (any Host accepted) · High on loopback, Medium otherwise
correct targetgood/mcp 400s on Host mismatch

Run only this check

reap -t https://your-host/mcp --authorized --include mcp-host-header-validation

Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.