CanopiiCanopiiAll serversEnterprise →
InfoAuth & transport

MCP servers that fail: origin validated (dns-rebinding protection)

5 of the 217 Model Context Protocol servers where this control could be evaluated fail it — that is 2% of the evaluated corpus on the Canopii Trust Index.

Servers failing
5
Failure rate
2%
Average score when failing
75/100

A further 171 servers warn on this control — a weaker signal we could not confirm, counted at half weight rather than as a failure.

Why this matters

An HTTP MCP server that doesn't reject hostile Origin headers can be driven by any web page the user visits via DNS rebinding — including servers bound to localhost (CIS MCP 2.5).

How to pass it

Enable the SDK's DNS-rebinding protection (enableDnsRebindingProtection / TransportSecuritySettings) with explicit allowed hosts and origins, and return 403 for an unlisted Origin.

Control id transport.origin_validated — weighted 4 in the rubric.

Affected servers

Each server's own page shows the evidence behind this result.

This control is one of 32 in the published rubric — see how scoring works or how the ecosystem fails every other control.