Affected by GO-2026-5996
and 2 other vulnerabilities
GO-2026-5996: ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway in github.com/stacklok/toolhive
GO-2026-6002: ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation) in github.com/stacklok/toolhive
GO-2026-6526: ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement in github.com/stacklok/toolhive
Decrypt decrypts data using 256-bit AES-GCM. This both hides the content of
the data and provides a check that it hasn't been altered. Expects input
form nonce|ciphertext|tag where '|' indicates concatenation.
Encrypt encrypts data using 256-bit AES-GCM. This both hides the content of
the data and provides a check that it hasn't been altered. Output takes the
form nonce|ciphertext|tag where '|' indicates concatenation.