Security: modelcontextprotocol/python-sdk
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Client fetched server-chosen $ref URLs while validating tool results against output schemasGHSA-rwrf-2pqf-9j8j published
Sep 28, 2026 by maxisbeyModerate -
Streamable HTTP sessions were never reclaimed by default and kept their initialize payloadsGHSA-84m7-p3x7-pcfv published
Sep 30, 2026 by maxisbeyHigh -
Server bearer-token authentication accepts tokens issued for a different resource serverGHSA-w4fh-qvv9-3v23 published
Oct 5, 2026 by maxisbeyModerate -
HTTP client transports followed cross-origin redirects carrying custom headers and bodiesGHSA-5h93-6whr-6q8j published
Oct 2, 2026 by maxisbeyModerate -
Experimental task handlers allow any client to access and cancel other clients' tasksGHSA-hvrp-rf83-w775 published
Jun 5, 2026 by maxisbeyHigh -
OAuth client could send credentials to an authorization server chosen by the MCP serverGHSA-qx49-fqc8-xw99 published
Sep 28, 2026 by maxisbeyHigh -
HTTP server transports and OAuth endpoints read request bodies with no size limitGHSA-fmmv-w9g8-j3gc published
Sep 30, 2026 by maxisbeyHigh -
WebSocket server transport does not support Host/Origin validationGHSA-vj7q-gjh5-988w published
Jul 7, 2026 by maxisbeyHigh -
HTTP transports serve session requests without verifying the authenticated principalGHSA-jpw9-pfvf-9f58 published
Jun 5, 2026 by maxisbeyHigh -
DNS Rebinding Protection Disabled by Default in Model Context Protocol Python SDK for Servers Running on LocalhostGHSA-9h52-p55h-vw2f published
Dec 2, 2025 by pcarletonHigh