v2.5.1
Release v2.5.1
Release type: stable
Release line: 2.5.x
Branch: release/2.5.x
[2.5.1] - 2026-07-21
Added
- Introduced IP connection pinning feature using a custom
lookupin Node.js environments, which ensures the socket connects to the validated IP, closing DNS-rebinding vulnerabilities. - Implemented manual redirect handling to re-validate each redirect, preventing automatic follow-through to potentially unsafe internal addresses.
- Added a cap on response body size for the Node.js transport, defaulting to 10 MiB.
Changed
- Modified the DNS resolution process to signal unavailability on non-Node runtimes with a
SsrfResolverUnavailableError. This allows processing to proceed with literal-address checks while acknowledging platform limitations.
Fixed
- Addressed potential issues with unresolvable hosts by ensuring URLs reject appropriately if DNS resolution fails outside the edge environment.
Security
- Strengthened SSRF protections by incorporating mandatory address validation and connection pinning, thereby mitigating risks through layer-by-layer validation and control over DNS resolution and redirection.
Installation
npm install mcp-from-openapi@2.5.1