Back

HIGH

MCP Python SDK has Unhandled Exception in Streamable HTTP Transport ,Leading to Denial of Service

Published Jul 4, 2025

Description

The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.10.0, if a client deliberately triggers an exception after establishing a streamable HTTP session, this can lead to an uncaught ClosedResourceError on the server side, causing the server to crash and requiring a restart to restore service. Impact may vary depending on the deployment conditions, and presence of infrastructure-level resilience measures. Version 1.10.0 contains a patch for the issue.

Affected products

Remediation

Red Hat statement

The severity of this vulnerability is rated Moderate, as it does not impact system availability. The effects are confined to the application layer without compromising the underlying system stability.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

Weaknesses (1)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 4, 2025
Updated Jul 8, 2025
Reserved Jun 27, 2025
CISA Vulnrichment
Updated Jul 8, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 4, 2025
GHSA-J975-95F5-7WQH