Skip to content

MCP Routing-Header / Body Method Desync (Gateway Authz Bypass)

mcp-method-desync is a high severity check in the ai category, written in python. Its source is templates/ai/mcp/mcp-method-desync.py in cert-x-gen-templates.

ACTIVE check. The MCP 2026-07-28 stateless-core adds Mcp-Method / Mcp-Name request headers so a gateway can authorize a call WITHOUT parsing the JSON body. This proves, by observation, that a server dispatches on the BODY while the header claimed a different, benign method - so a gateway that trusted the header is bypassable. Sends a matched control (header and body agree) then a mismatched probe (header says tools/list, body calls a privileged tools/call). Server honours the body under the benign header => request smuggling / authz bypass.

Field Value
Id mcp-method-desync
Severity high
Language python
Category ai
Author Bugb Research
Template version 1.0.0
Confidence 95
CVSS 8.1
Weakness CWE-444, CWE-863
Tags mcp, ai, agent, request-smuggling, gateway, authz-bypass, desync, routing-header, behavioural, active, http, cwe-444, cwe-863
Target kind http
Oracle property

Declared in the header. cxg parses @references and then discards it, and nothing at scan time reads it, so this is the only place the links a template cites are surfaced.

To see what the copy on your machine says about itself, and to confirm it is installed at all:

Terminal window
cxg template info mcp-method-desync

The id it prints is the one to pass anywhere a template is selected. See cxg template for the rest of the subcommand, Scan a target for running a scan, and A match is not a finding for how to read what comes back.