Mcp Python Sdk
Lfprojects · 4 CVEs
CVE-2026-59950
HIGH
MCP Python SDK: WebSocket server transport does not support Host/Origin validation
Jul 15, 2026
CVE-2026-52870
HIGH
MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
Jul 15, 2026
CVE-2026-52869
HIGH
MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
Jul 15, 2026
CVE-2025-66416
HIGH
DNS Rebinding Protection Disabled by Default in Model Context Protocol Python SDK for Servers Running on Localhost
Dec 2, 2025
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-59950 | MCP Python SDK: WebSocket server transport does not support Host/Origin validation | HIGH | 0.23% | Jul 15, 2026 |
| CVE-2026-52870 | MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks | HIGH | 0.39% | Jul 15, 2026 |
| CVE-2026-52869 | MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal | HIGH | 0.53% | Jul 15, 2026 |
| CVE-2025-66416 | DNS Rebinding Protection Disabled by Default in Model Context Protocol Python SDK for Servers Running on Localhost | HIGH | 0.51% | Dec 2, 2025 |
Showing 1 to 4 of 4 CVEs