reap / rules / auth and session posture
MCP accepted initialize with a mismatched Host header
mcp-host-header-validation ASI03 Identity and Privilege Abuse severity: medium (high on loopback)
What it detects
Server doesn't validate Host during initialize (DNS rebinding exposure). ASI03. Severity is conditional: Medium by default, High only for loopback targets, where a browser-driven rebinding attack reaches a local agent directly — see the calibration note in docs/ASI_MAPPING.md.
Sends initialize with a mismatched Host header; flags servers that process it anyway (no host-name validation). Conditional severity: see docs/ASI_MAPPING.md calibration note.
applies to MCP endpoints
Why it matters
DNS rebinding lets a web page reach an agent endpoint and act with the victim's network position.
Example finding
HIGH mcp-host-header-validation HIGH CONFIDENCE MCP accepted initialize with a mismatched Host header The server processed an initialize request even though the Host header was set to "host-header-validation.invalid", so it does not validate the requested host name before handling MCP traffic. This is the condition DNS-rebinding protection prevents; it is rated high only for loopback endpoints, where a browser-driven rebinding attack reaches a local agent directly. Evidence POST /mcp → 200
from a scan of reap-range, bad target
Fix
Validate the Host header or equivalent request target before accepting MCP requests, and refuse requests whose host name does not match the configured endpoint.
On reap-range
| insecure target | bad/mcp (any Host accepted) · High on loopback, Medium otherwise |
| correct target | good/mcp 400s on Host mismatch |
Run only this check
reap -t https://your-host/mcp --authorized --include mcp-host-header-validation
Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.