{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "source": "REFERENCES"
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "e6b3032cfc906e14f5b84f2c2b8ec378eb457e57"
            },
            {
              "fixed": "efba6fa01232dacb1480bbcfdf1eeb2cf2c09723"
            }
          ],
          "repo": "https://github.com/leshchenko1979/fast-mcp-telegram",
          "type": "GIT"
        }
      ]
    }
  ],
  "aliases": [
    "GHSA-xr72-j7vj-vp7g"
  ],
  "database_specific": {
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
      "CWE-184",
      "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55096.json",
    "unresolved_ranges": [
      {
        "extracted_events": [
          {
            "fixed": "30.1"
          }
        ],
        "source": "AFFECTED_FIELD"
      }
    ]
  },
  "details": "fast-mcp-telegram is a Telegram MCP Server. Prior to version 30.1, the send_message/send_message_to_phone MCP tools accept files as a list of http(s) URLs, which the server downloads and attaches to the outgoing Telegram message. Downloads are guarded by _validate_url_security, an SSRF denylist that checks the URL's literal hostname string but never resolves DNS. The fetch (httpx.AsyncClient.get) does its own resolution at request time. Consequently a hostname that resolves to a loopback / private / link-local address passes the guard and is fetched — even with the secure defaults block_private_ips=True and allow_http_urls=False. Because the fetched body is returned to the attacker as a Telegram file attachment, this is a full-read, exfiltrating SSRF, not blind. This issue has been patched in version 30.1.",
  "id": "CVE-2026-55096",
  "modified": "2026-09-30T03:31:04.004554409Z",
  "published": "2026-09-28T16:38:26.730Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/leshchenko1979/fast-mcp-telegram/releases/tag/0.30.1"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55096.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/leshchenko1979/fast-mcp-telegram/security/advisories/GHSA-xr72-j7vj-vp7g"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55096"
    },
    {
      "type": "FIX",
      "url": "https://github.com/leshchenko1979/fast-mcp-telegram/commit/e6b3032cfc906e14f5b84f2c2b8ec378eb457e57"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "SSRF via DNS-resolution gap in _validate_url_security (file download by URL)"
}