Modelcontextprotocol / Python-Sdk
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-59950 | MCP Python SDK: WebSocket server transport does not support Host/Origin validation | HIGH | 7.6 | Jul 15, 2026 |
| CVE-2026-52870 | MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks | HIGH | 7.6 | Jul 15, 2026 |
| CVE-2026-52869 | MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal | HIGH | 7.1 | Jul 15, 2026 |
| CVE-2025-66416 | DNS Rebinding Protection Disabled by Default in Model Context Protocol Python SDK for Servers Running on Localhost | HIGH | 7.6 | Dec 2, 2025 |
| CVE-2025-53366 | MCP SDK Vulnerable to FastMCP Server Validation Error, Leading to Denial of Service | HIGH | 8.7 | Jul 4, 2025 |
| CVE-2025-53365 | MCP Python SDK has Unhandled Exception in Streamable HTTP Transport ,Leading to Denial of Service | HIGH | 8.7 | Jul 4, 2025 |
Showing 1 to 6 of 6 CVEs