mcp-atlassian is vulnerable to Denial of Service (DoS)
35
Low Risk
Affected versions of this package are vulnerable to uncontrolled resource consumption due to missing explicit timeout configuration on HTTP requests in the OAuth flow, which can cause connections to hang indefinitely when Atlassian APIs are slow or unresponsive. The issue impacts OAuth token exchange, token refresh, and cloud ID retrieval requests in src/mcp_atlassian/utils/oauth.py. Explicit connection (5 seconds) and read (20 seconds) timeouts mitigate the risk by preventing stalled connections and improving overall reliability.
You are affected if you are using a version that falls within the vulnerable range.
mcp-atlassian is vulnerable to Denial of Service (DoS) in versions 0.1.0 - 0.11.12.
Upgrade the mcp-atlassian library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant