Skip to content

chore(ci): ignore RUSTSEC-2026-0189 (rmcp HTTP transport not used) - #41

Merged
cuihtlauac merged 1 commit into
mainfrom
chore/ignore-rustsec-2026-0189
Sep 7, 2026
Merged

cuihtlauac merged 1 commit into
mainfrom
chore/ignore-rustsec-2026-0189

Conversation

@cuihtlauac

Copy link
Copy Markdown
Member

cargo audit and cargo deny on main fail on RUSTSEC-2026-0189 — a DNS-rebinding flaw (missing Host-header validation) in rmcp's Streamable HTTP server transport.

sudo-proxy is not affected:

  • The advisory explicitly excludes non-HTTP transports: "stdio and child-process transports are not affected."
  • Cargo.toml enables only rmcp's transport-io feature — the HTTP/streamable-http server transport is not compiled in.
  • The MCP server is served over stdio: McpProxy::new().serve(stdio()) (src/bin/sudo-proxy-mcp.rs). There is no HTTP listener for a rebinding attack to reach.

This suppresses the false positive in both advisory gates, with the rationale documented inline:

  • deny.toml → [advisories].ignore
  • the cargo audit step → --ignore RUSTSEC-2026-0189

Both cargo deny check advisories and cargo audit --ignore RUSTSEC-2026-0189 pass locally. Revisit if an HTTP transport is ever added.

🤖 Generated with Claude Code

The advisory is a DNS-rebinding flaw in rmcp's Streamable HTTP server
transport (missing Host-header validation). sudo-proxy is not affected:
the advisory explicitly excludes non-HTTP transports, and this crate
enables only rmcp's `transport-io` feature and serves the MCP server
over stdio (src/bin/sudo-proxy-mcp.rs). The vulnerable HTTP transport is
not compiled in.

Document the rationale and ignore the ID in both advisory gates:
deny.toml [advisories].ignore and the `cargo audit` step.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
@cuihtlauac
cuihtlauac merged commit 484d965 into main Sep 7, 2026
16 checks passed
@cuihtlauac
cuihtlauac deleted the chore/ignore-rustsec-2026-0189 branch September 7, 2026 09:26
cuihtlauac added a commit that referenced this pull request Sep 7, 2026
…triage (#42)

Changelog: add a 2026-09-07 entry (release/hygiene, not a ladder rung)
covering the publication of io.github.tarides/sudo-proxy 1.0.0 to the
official MCP Registry once cargo support shipped upstream, the removal
of the obsolete registry-watch tripwire (PR #40), and the
RUSTSEC-2026-0189 not-applicable triage and suppression (PR #41).

Backlog: capture one contingent follow-up — re-evaluate the
RUSTSEC-2026-0189 ignore if an HTTP transport is ever added. The
current assurance-ladder task is unchanged.

Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant