CWE-350: Reliance on Reverse DNS Resolution for a Security-Critical Action
The product performs reverse DNS resolution on an IP address to obtain the hostname and make a security decision, but it does not properly ensure that the IP address is truly associated with the hostname.
23 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-1490 — Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.71 - Authorization Bypass via Reverse DNS (PTR record) Spoofing to Unauthenticated Arbitrary Plugin Installation
- CVE-2026-42559 — RMCP: DNS rebinding vulnerability in rmcp Streamable HTTP server transport
- CVE-2026-56709 — Grav before 3.9.2 Host Header Injection via sendInvitationEmail
- CVE-2026-55526 — PraisonAI: SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
- CVE-2026-28271 — Kiteworks Core is vulnerable to Server-Side Request Forgery (SSRF)
- CVE-2025-59956 — AgentAPI exposed user chat history via a DNS rebinding attack
- CVE-2025-24010 — Vite allows any websites to send any requests to the development server and read the response
- CVE-2024-42364 — homepage DNS rebinding vulnerability (GHSL-2024-096)
- CVE-2026-55391 — datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
- CVE-2026-63118 — MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
- CVE-2024-53275 — GHSL-2024-091: DNS rebinding attack in home-gallery
- CVE-2026-75514 — BunkerWeb: rDNS bypass via missing forward-confirmation (FCrDNS) in blacklist, greylist, and antibot
- CVE-2026-6874 — ericc-ch copilot-api Header token dns rebinding
- CVE-2026-46611 — Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack
- CVE-2025-59163 — vet MCP Server SSE Transport DNS Rebinding Vulnerability
- CVE-2026-24281 — Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
- CVE-2026-12635 — Reliance on Reverse DNS Resolution for a Security-Critical Action in GitLab
Recently published
- CVE-2026-55526 — PraisonAI: SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
- CVE-2026-56709 — Grav before 3.9.2 Host Header Injection via sendInvitationEmail
- CVE-2026-75514 — BunkerWeb: rDNS bypass via missing forward-confirmation (FCrDNS) in blacklist, greylist, and antibot
- CVE-2026-63118 — MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
- CVE-2026-55391 — datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
- CVE-2026-46611 — Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack
- CVE-2026-12635 — Reliance on Reverse DNS Resolution for a Security-Critical Action in GitLab
- CVE-2026-42559 — RMCP: DNS rebinding vulnerability in rmcp Streamable HTTP server transport
- CVE-2026-6874 — ericc-ch copilot-api Header token dns rebinding
- CVE-2026-24281 — Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
- CVE-2026-28271 — Kiteworks Core is vulnerable to Server-Side Request Forgery (SSRF)
- CVE-2026-1490 — Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.71 - Authorization Bypass via Reverse DNS (PTR record) Spoofing to Unauthenticated Arbitrary Plugin Installation
- CVE-2025-59956 — AgentAPI exposed user chat history via a DNS rebinding attack
- CVE-2025-59163 — vet MCP Server SSE Transport DNS Rebinding Vulnerability
- CVE-2025-24010 — Vite allows any websites to send any requests to the development server and read the response
- CVE-2024-53275 — GHSL-2024-091: DNS rebinding attack in home-gallery
- CVE-2024-42364 — homepage DNS rebinding vulnerability (GHSL-2024-096)