CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1
CVE-2026-59950 HIGH
MCP Python SDK: WebSocket server transport does not support Host/Origin validation
CVSS 7.6 EPSS 0.23% Jul 15, 2026
CVE-2026-52870 HIGH
MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
CVSS 7.6 EPSS 0.39% Jul 15, 2026
CVE-2026-52869 HIGH
MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
CVSS 7.1 EPSS 0.53% Jul 15, 2026
CVE-2025-66416 HIGH
DNS Rebinding Protection Disabled by Default in Model Context Protocol Python SDK for Servers Running on Localhost
CVSS 7.6 EPSS 0.51% Dec 2, 2025
CVE-2025-53366 HIGH
MCP SDK Vulnerable to FastMCP Server Validation Error, Leading to Denial of Service
CVSS 8.7 EPSS 7.69% Jul 4, 2025
CVE-2025-53365 HIGH
MCP Python SDK has Unhandled Exception in Streamable HTTP Transport ,Leading to Denial of Service
CVSS 8.7 EPSS 0.39% Jul 4, 2025
Showing 1 to 6 CVEs · page 1