—
GO-2025-4179
Docker MCP Plugin and Docker MCP Gateway have DNS Rebinding vulnerability when running in sse or streaming mode in github.com/docker/mcp-gateway
Quick fix
GO-2025-4179 — github.com/docker/mcp-gateway: upgrade to the fixed version with the command below.
go get github.com/docker/mcp-gateway@v0.28.0Details
Docker MCP Plugin and Docker MCP Gateway have DNS Rebinding vulnerability when running in sse or streaming mode in github.com/docker/mcp-gateway
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/docker/mcp-gateway
Introduced in:
0Fixed in: 0.28.0Fix
go get github.com/docker/mcp-gateway@v0.28.0References
- https://github.com/docker/mcp-gateway/security/advisories/GHSA-46gc-mwh4-cc5r[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2025-64443[ADVISORY]
- https://github.com/docker/mcp-gateway/commit/6b076b2479d8d1345c50c112119c62978d46858e[FIX]
- https://github.com/docker/mcp-gateway/commit/fe073985c8eb6e0c9317d2f198c07686f70ea06d[FIX]
- https://github.com/docker/mcp-gateway/pull/190[FIX]
- https://modelcontextprotocol.io/specification/2025-06-18/basic/transports#security-warning[WEB]