Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

rmcp (official Rust MCP SDK): default Streamable HTTP client never follows spec-permitted redirects - redirecting MCP servers hard-fail with Err(UnexpectedServerResponse)

オープン
#1,203 コメント 3 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 3 日以内に返信

@dawNotPoi がすでに取り組んでいます。

2026年8月23日 から。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
45/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
活発
技術スタック
rust
領域
api, networking

調査の方向性

crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs の StreamableHttpClientTransport::default_http_client() から始め、リダイレクト時のカスタムヘッダー漏洩を対象とする既存の単体テストを確認してください。issue にある 307 のケースを再現し、安全なリダイレクトポリシーと設定可能なポリシーのどちらが意図されているかを判断してください。MCP サーバーへのリダイレクトが、カスタムヘッダーを安全でない形で再送することなく機能し、既存の動作と関連するテストがそれに応じて更新されていれば完了です。

索引モデルが issue の本文から書いたものです。

説明

P2 T-enhancement T-transport

rmcp (official Rust MCP SDK): default Streamable HTTP client never follows spec-permitted redirects

Type: functional / MCP conformance
Component: crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs — StreamableHttpClientTransport::default_http_client()

Summary

The official Rust SDK's default Streamable HTTP client is built with:

reqwest::Client::builder()
    .pool_max_idle_per_host(0)
    .redirect(reqwest::redirect::Policy::none())
    .build()

so it never follows HTTP redirects. The MCP spec explicitly permits servers to respond to transport requests with 301/302/307/308 (load balancing, canonical URL / trailing-slash normalization — see e.g. https://github.com/IBM/mcp-context-forge#4441 for a real 307 on /mcp/). Against any redirecting server, every request degrades to:

Err(StreamableHttpError::UnexpectedServerResponse("HTTP 307: ..."))

and the client cannot talk to that server at all.

The truncation is deliberate (there is a unit test asserting no custom-header leak to a redirect target — sensible given reqwest's default policy would replay custom headers), but the consequence is that a spec-compliant redirecting MCP server is unsupported out of the box.

Repro (no build needed)

Point any rmcp StreamableHttpClientTransport (default client) at a server that answers POST /mcp with 307 Location: <same-origin>/v2/mcp. Every post_message returns UnexpectedServerResponse("HTTP 307: ...") instead of issuing a follow-up request to the new Location.

A self-contained crate reproducing this (and the goose-side contrast) is at https://github.com/trickyfalcon/cve-hunt/blob/main/poc-goose-rust/ — scenario B prints the Err(UnexpectedServerResponse("HTTP 307: ...")) directly.

Suggested direction

Follow redirects safely rather than never: only follow cross-host/cross-lo*...* leftovers to be trimmed — or, at minimum, make redirect policy configurable on StreamableHttpClientTransportConfig while keeping the default strict (no-follow) for backwards compatibility. An explicit redirect policy override (as an associated constructor option) would let security-conscious users opt in to same-origin redirect following.

Environment

  • rmcp via modelcontextprotocol/rust-sdk (checked out 2026-08-22, rmcp crate 3.x)
  • Reproducible with the PoC referenced above

Happy to be credited in the advisory/release notes as: Mo (@trickyfalcon, https://trickyfalcon.com)

主要言語
Rust
スター
4k
フォーク
654
平均マージ
3日 15時間
マージ済み PR(30日)
37

環境構築

Codespaces で開く

このプロジェクトの開発コンテナを、あなたの GitHub アカウントでブラウザ上に起動します。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

modelcontextprotocol/rust-sdk のほかの issue

modelcontextprotocol/rust-sdk の issue をすべて見る

似ている issue

Rust の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。