Skip to content

fix(transport-security): compare Host and Origin case-insensitively (#3437) - #3455

Closed
amasen02 wants to merge 1 commit into
modelcontextprotocol:mainfrom
amasen02:fix/transport-security-case-insensitive-host-3437
Closed

fix(transport-security): compare Host and Origin case-insensitively (#3437)#3455
amasen02 wants to merge 1 commit into
modelcontextprotocol:mainfrom
amasen02:fix/transport-security-case-insensitive-host-3437

Conversation

@amasen02

@amasen02 amasen02 commented Sep 5, 2026

Copy link
Copy Markdown

Summary

Fixes #3437.

TransportSecurityMiddleware._validate_host() and _validate_origin() previously compared incoming Host and Origin headers against allowed_hosts and allowed_origins case-sensitively.

Per RFC 9110 §4.2.3 and RFC 6454 §4:

  • "The scheme and host are case-insensitive and normally provided in lowercase; all other components are compared in a case-sensitive manner."

Every WHATWG URL-based HTTP client (browsers, Node fetch, undici, and mcp-remote) automatically lowercases hostnames before transmitting them. On Windows, where %COMPUTERNAME% is uppercase by default, configuring allowed_hosts=["MYHOST:*"] caused all incoming requests from standard fetch clients (e.g. Host: myhost:8000) to be rejected with 421 Misdirected Request.

Changes

  • In src/mcp/server/transport_security.py:
    • _validate_host(): Lowercases both the incoming Host header and allowed_hosts items before exact and wildcard-port comparisons.
    • _validate_origin(): Lowercases both the incoming Origin header and allowed_origins items before exact and wildcard-port comparisons.
  • In tests/server/test_transport_security.py:
    • Added test cases covering uppercase and mixed-case Host and Origin values against lowercase allowlists.
    • Added test_validate_request_case_insensitive_uppercase_settings asserting that uppercase allowlist configurations (such as Windows %COMPUTERNAME%) correctly permit lowercase client requests.

Verification

  • Ran uv run pytest tests/server/test_transport_security.py: 31/31 passed in 0.11s.
  • Checked with uv run ruff check and uv run ruff format --check: 100% clean.

…odelcontextprotocol#3437)

Normalize host and origin headers and allowed entries to lowercase per RFC 9110 and RFC 6454 so uppercase host configurations (e.g. %COMPUTERNAME% on Windows) correctly match fetch-based lowercase clients.
@github-actions github-actions Bot added the missing-issue-link Auto-closed: PR needs a linked issue assigned to its author (see CONTRIBUTING.md) label Sep 5, 2026
@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

This PR has been closed automatically. This repo only keeps pull requests open when they come from a maintainer, or from a contributor a maintainer has assigned to the linked issue, and you aren't currently assigned to #3437.

If a maintainer assigns you to #3437, this PR reopens on its own and there's nothing more you need to do here. Assignment is a maintainer call based on capacity; comments that only ask to be assigned don't factor in. What does help is engaging on the issue itself by confirming the repro, explaining why it matters for your use case, or describing the approach you'd take.

You're welcome to keep pushing commits here (just avoid force-pushing, since GitHub can't reopen a rewritten branch), but that on its own won't get the PR reviewed or the issue assigned, and realistically most auto-closed PRs stay closed. There's no need to open a new PR either way.

CONTRIBUTING.md has the full reasoning, but in short:

  • We're a small team with very little capacity to review community PRs right now.
  • Many recent PRs are AI-generated with little human review, and reviewing one carefully still costs a maintainer as much time as it ever did. A well-described issue is usually more useful to us than the code.

Maintainers: reopen, remove missing-issue-link, or add bypass-issue-check to override.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

missing-issue-link Auto-closed: PR needs a linked issue assigned to its author (see CONTRIBUTING.md)

Projects

None yet

1 participant