Skip to content

Modify Origin header validation in validateRequestHeaders (streamableHttp.ts and sse.ts) to allow requests without an Origin, as they are not relevant to server DNS rebinding protection.#1205

Merged
pcarleton merged 1 commit intomodelcontextprotocol:mainfrom
jacopoc:improve-header-validation-for-dns-rebinding-protection
Dec 2, 2025