Skip to main content
HIGH

CVE-2026-55096

CVSS v3

7.1

HIGH

EPSS Score

—

exploit probability

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

fast-mcp-telegram is a Telegram MCP Server. Prior to version 30.1, the send_message/send_message_to_phone MCP tools accept files as a list of http(s) URLs, which the server downloads and attaches to the outgoing Telegram message. Downloads are guarded by _validate_url_security, an SSRF denylist that checks the URL's literal hostname string but never resolves DNS. The fetch (httpx.AsyncClient.get) does its own resolution at request time. Consequently a hostname that resolves to a loopback / priva

Technical details

CVSS v3 Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Published
2026-09-28
Last Modified
2026-09-28

Frequently asked questions

What is CVE-2026-55096?

fast-mcp-telegram is a Telegram MCP Server. Prior to version 30.1, the send_message/send_message_to_phone MCP tools accept files as a list of http(s) URLs, which the server downloads and attaches to the outgoing Telegram message. Downloads are guarded by _validate_url_security, an SSRF denylist that checks the URL's literal hostname string but never resolves DNS. The fetch (httpx.AsyncClient.get) does its own resolution at request time. Consequently a hostname that resolves to a loopback / priva

Is CVE-2026-55096 actively exploited?

Active exploitation of CVE-2026-55096 has not been confirmed.

What is the CVSS score for CVE-2026-55096?

CVE-2026-55096 has a CVSS v3 base score of 7.1 (HIGH severity), with vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N.

Is CVE-2026-55096 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key