MCP Python SDK has Unhandled Exception in Streamable HTTP Transport ,Leading to Denial of Service
Published Jul 4, 2025
8.7
HIGHCVSS 4.0
EPSS 0.39%
Description
The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.10.0, if a client deliberately triggers an exception after establishing a streamable HTTP session, this can lead to an uncaught ClosedResourceError on the server side, causing the server to crash and requiring a restart to restore service. Impact may vary depending on the deployment conditions, and presence of infrastructure-level resilience measures. Version 1.10.0 contains a patch for the issue.
Affected products
-
- Version < 1.10.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Modelcontextprotocol | Python-Sdk | n/a |
|
No data.
No data.
OpenShift Lightspeed
openshift-lightspeed/lightspeed-service-api-rhel9
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-service-api-rhel9 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The severity of this vulnerability is rated Moderate, as it does not impact system availability. The effects are confined to the application layer without compromising the underlying system stability.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Jul 8, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.39% (0.00390) | 30.68th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.35% (0.00353) | 26.90th | v5 (v2026.06.15) |
| Jul 5, 2025 | 0.04% (0.00040) | 11.29th | v4 (v2025.03.14) |
References (12)
- https://access.redhat.com/security/cve/CVE-2025-53365 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2376486 Issue Tracking
- https://github.com/advisories/GHSA-j975-95f5-7wqh Advisory
- https://github.com/modelcontextprotocol/python-sdk
- https://github.com/modelcontextprotocol/python-sdk/commit/7b420656de48cfdb90b39eb582e60b6d55c2f891 x_refsource_MISC
- https://github.com/modelcontextprotocol/python-sdk/pull/967 x_refsource_MISC
- https://github.com/modelcontextprotocol/python-sdk/releases/tag/v1.10.0
- https://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-j975-95f5-7wqh x_refsource_CONFIRM
- https://github.com/pypa/advisory-database/tree/main/vulns/mcp/PYSEC-2026-1618.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2025-53365
- https://pypi.org/project/mcp
- https://www.cve.org/CVERecord?id=CVE-2025-53365
Change history (0)
No recorded changes yet.