Update dependency mcp to v1.28.1 [SECURITY]#8
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Caution Review the following alerts detected in dependencies. According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.
|
2e7e1eb to
325adb7
Compare
cd7d2f9 to
32ff8a8
Compare
32ff8a8 to
290ab6f
Compare
290ab6f to
5641911
Compare
5641911 to
3f8e811
Compare
3f8e811 to
abb0144
Compare
abb0144 to
9c73472
Compare
9c73472 to
fa88e2b
Compare
fa88e2b to
6bdacd0
Compare
6bdacd0 to
0707fc4
Compare
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
0707fc4 to
95a48d4
Compare
This PR contains the following updates:
1.9.1→1.28.1MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS
CVE-2025-53366 / GHSA-3qhf-m339-9g5v / PYSEC-2026-1616
More information
Details
A validation error in the MCP SDK can cause an unhandled exception when processing malformed requests, resulting in service unavailability (500 errors) until manually restarted. Impact may vary depending on the deployment conditions, and presence of infrastructure-level resilience measures.
Thank you to Rich Harang for reporting this issue.
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS
CVE-2025-53366 / GHSA-3qhf-m339-9g5v / PYSEC-2026-1616
More information
Details
A validation error in the MCP SDK can cause an unhandled exception when processing malformed requests, resulting in service unavailability (500 errors) until manually restarted. Impact may vary depending on the deployment conditions, and presence of infrastructure-level resilience measures.
Thank you to Rich Harang for reporting this issue.
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:NReferences
This data is provided by OSV and the PyPI Advisory Database (CC-BY 4.0).
MCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service
CVE-2025-53365 / GHSA-j975-95f5-7wqh / PYSEC-2026-1618
More information
Details
If a client deliberately triggers an exception after establishing a streamable HTTP session, this can lead to an uncaught ClosedResourceError on the server side, causing the server to crash and requiring a restart to restore service. Impact may vary depending on the deployment conditions, and presence of infrastructure-level resilience measures.
Thank you to Rich Harang for reporting this issue.
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
MCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service
CVE-2025-53365 / GHSA-j975-95f5-7wqh / PYSEC-2026-1618
More information
Details
If a client deliberately triggers an exception after establishing a streamable HTTP session, this can lead to an uncaught ClosedResourceError on the server side, causing the server to crash and requiring a restart to restore service. Impact may vary depending on the deployment conditions, and presence of infrastructure-level resilience measures.
Thank you to Rich Harang for reporting this issue.
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:NReferences
This data is provided by OSV and the PyPI Advisory Database (CC-BY 4.0).
Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default
CVE-2025-66416 / GHSA-9h52-p55h-vw2f / PYSEC-2026-1617
More information
Details
Description
The Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on localhost without authentication using
FastMCPwith streamable HTTP or SSE transport, and has not configuredTransportSecuritySettings, a malicious website could exploit DNS rebinding to bypass same-origin policy restrictions and send requests to the local MCP server. This could allow an attacker to invoke tools or access resources exposed by the MCP server on behalf of the user in those limited circumstances.Note that running HTTP-based MCP servers locally without authentication is not recommended per MCP security best practices. This issue does not affect servers using stdio transport.
Servers created via
FastMCP()now have DNS rebinding protection enabled by default when thehostparameter is127.0.0.1orlocalhost. Users are advised to update to version1.23.0to receive this automatic protection. Users with custom low-level server configurations usingStreamableHTTPSessionManagerorSseServerTransportdirectly should explicitly configureTransportSecuritySettingswhen running an unauthenticated server on localhost.Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default
CVE-2025-66416 / GHSA-9h52-p55h-vw2f / PYSEC-2026-1617
More information
Details
Description
The Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on localhost without authentication using
FastMCPwith streamable HTTP or SSE transport, and has not configuredTransportSecuritySettings, a malicious website could exploit DNS rebinding to bypass same-origin policy restrictions and send requests to the local MCP server. This could allow an attacker to invoke tools or access resources exposed by the MCP server on behalf of the user in those limited circumstances.Note that running HTTP-based MCP servers locally without authentication is not recommended per MCP security best practices. This issue does not affect servers using stdio transport.
Servers created via
FastMCP()now have DNS rebinding protection enabled by default when thehostparameter is127.0.0.1orlocalhost. Users are advised to update to version1.23.0to receive this automatic protection. Users with custom low-level server configurations usingStreamableHTTPSessionManagerorSseServerTransportdirectly should explicitly configureTransportSecuritySettingswhen running an unauthenticated server on localhost.Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by OSV and the PyPI Advisory Database (CC-BY 4.0).
MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
CVE-2026-52869 / GHSA-jpw9-pfvf-9f58
More information
Details
Summary
In affected versions, the SSE and Streamable HTTP server transports routed incoming requests to an existing session based only on the session identifier, without verifying that the request was authenticated as the same principal that created the session. Anyone who learned or guessed a session ID could send JSON-RPC messages on that session, regardless of which bearer token the request carried.
Am I affected?
Only if a developer's application server uses an HTTP transport (SSE, or Streamable HTTP in stateful mode) and authenticates requests. Servers on stdio, stateless Streamable HTTP, or with no authentication configured are not affected.
Details
Both transports look up the target session by its identifier alone — the
session_idquery parameter for SSE (mcp.server.sse.SseServerTransport) and theMcp-Session-Idheader for Streamable HTTP (mcp.server.streamable_http_manager.StreamableHTTPSessionManager). Once the lookup succeeded, the request was handled on that session without comparing its authentication context to the credentials presented when the session was created, so a request authenticated as a different OAuth client could inject messages into the session. On the SSE transport the response is delivered to the original client's event stream; on the Streamable HTTP transport it is returned on the injecting request, so the injecting client can also read the result. The SSE transport has been affected since the first release; the Streamable HTTP transport since version 1.8.0.Impact
Servers using either HTTP transport together with the SDK's built-in bearer-token authentication are affected: the per-client isolation that authentication provides can be bypassed for any session whose ID is known. Session IDs are randomly generated UUIDs, so exploitation requires obtaining one out of band (logs, network observation). Servers that do not enable bearer-token authentication have no per-client isolation to bypass and are not addressed by this advisory, and stateless Streamable HTTP deployments do not maintain sessions and are unaffected.
Mitigation
Upgrade to version 1.27.2 or later, which records the authenticated principal that created each session — the OAuth client ID together with the token's issuer and subject when the token verifier supplies them — and answers requests presenting a different principal with the same 404 response as for an unknown session.
Deployments where many end users share a single OAuth client (hosted MCP clients, gateways) should ensure their token verifier populates
AccessToken.subject(e.g. from the token'ssubclaim) so sessions are isolated per user rather than per client. Deployments using a custom authentication backend other than the built-inBearerAuthBackendshould enforce an equivalent check themselves.Severity
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:LReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
MCP Python SDK: WebSocket server transport does not support Host/Origin validation
CVE-2026-59950 / GHSA-vj7q-gjh5-988w
More information
Details
Summary
In affected versions, the deprecated WebSocket server transport (
mcp.server.websocket.websocket_server) accepted the WebSocket handshake without applying anyHostorOriginheader validation. TheTransportSecuritySettingsmechanism that the SSE and Streamable HTTP transports use for this purpose was not wired into the WebSocket transport, so there was no SDK-level way to restrict which origins could connect.Am I affected?
Only if a developer's application server exposes
mcp.server.websocket.websocket_server. This transport has never been part of the MCP specification, is marked deprecated, and is not reachable throughFastMCP— a developer must have wired it into an ASGI application themselves. Servers using stdio, SSE, or Streamable HTTP are not affected by this advisory.Details
websocket_server()constructed a StarletteWebSocketand calledaccept(subprotocol="mcp")immediately, with no inspection of the connection's headers. By contrast,SseServerTransportandStreamableHTTPServerTransportaccept an optionalsecurity_settings: TransportSecuritySettingsand runTransportSecurityMiddleware.validate_request()against the incomingHostandOriginheaders before establishing a session. Because browsers attach anOriginheader to cross-origin WebSocket upgrade requests but do not enforce a same-origin policy on the response, a web page served from any origin could open a WebSocket to a reachable MCP server on this transport, complete theinitializehandshake, and issue JSON-RPC requests on the resulting session.Impact
A user who runs an MCP server on this transport bound to localhost or a LAN address, without a separate authentication or origin gate in front of it, and visits a malicious web page, can have that page enumerate and invoke the server's tools and read its resources. The consequences depend entirely on what the server exposes. The transport itself requires no token or prior session. Some browsers prompt before allowing a public page to open a connection to a local-network address, which adds a user-interaction step but is not a substitute for server-side validation.
Mitigation
Upgrade to version 1.28.1 or later, in which
websocket_server()accepts the same optionalsecurity_settings: TransportSecuritySettingsargument as the other HTTP-based transports and validates theHostandOriginheaders before accepting the handshake; a request that fails validation is rejected with HTTP 403 andValueError("Request validation failed")is raised to the caller. As with the other transports the parameter defaults toNone, which leaves validation disabled, so upgrading alone does not change behaviour: pass aTransportSecuritySettingswithenable_dns_rebinding_protection=Trueand appropriateallowed_hosts/allowed_originsto receive the protection. The recommended path remains to migrate off this deprecated transport to Streamable HTTP, whereFastMCPenables this protection automatically for localhost binds. The WebSocket transport has been removed entirely in v2.Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
modelcontextprotocol/python-sdk (mcp)
v1.28.1Compare Source
What's Changed
Full Changelog: modelcontextprotocol/python-sdk@v1.28.0...v1.28.1
v1.28.0Compare Source
Deprecations
Two API surfaces now emit
DeprecationWarningahead of their removal in v2. Nothing is removed in 1.x, and the warnings fire only when the deprecated API is called - importing the modules stays silent.mcp.client.websocket.websocket_clientandmcp.server.websocket.websocket_server. WebSocket was never part of the MCP specification; use the streamable HTTP transport instead. The TypeScript SDK has likewise removed its WebSocket client for v2 (modelcontextprotocol/typescript-sdk#1783).ClientSession.experimental,Server.experimental,ServerSession.experimental, and theexperimental_task_handlers=kwarg onClientSession. Tasks (SEP-1686) were removed from the MCP specification and are expected to return as a separate MCP extension.If your test suite runs with
filterwarnings = ["error"]and exercises these paths, add a scoped ignore such asignore:The experimental tasks API is deprecated:DeprecationWarningorignore:The WebSocket .* transport is deprecated:DeprecationWarning.See #2828 for full details.
What's Changed
New Contributors
Full Changelog: modelcontextprotocol/python-sdk@v1.27.2...v1.28.0
v1.27.2Compare Source
What's Changed
Full Changelog: modelcontextprotocol/python-sdk@v1.27.1...v1.27.2
v1.27.1Compare Source
What's Changed
Full Changelog: modelcontextprotocol/python-sdk@v1.27.0...v1.27.1
v1.27.0Compare Source
What's Changed
requestsdependency from simple-chatbot example by @maxisbey in #1959New Contributors
Full Changelog: modelcontextprotocol/python-sdk@v1.26.0...v1.27.0
v1.26.0Compare Source
What's Changed
Full Changelog: modelcontextprotocol/python-sdk@v1.25.0...v1.26.0
v1.25.0Compare Source
Branching Update
Starting with this release, the repository has adopted a new branching strategy for v2 development:
main— v2 development (breaking changes)v1.x— v1 maintenance (security and critical bug fixes only, with very rare feature additions ported frommain)Users who need to stay on v1.x should pin to
mcp>=1.25,<2.The current plan is to work through v2 and have it released some time in Q1. This also relies on the next upcoming spec release which will heavily change how the transport layer works, which in turn will guide a lot of how we architect v2.
What's Changed
New Contributors
Full Changelog: modelcontextprotocol/python-sdk@v1.24.0...v1.25.0
v1.24.0Compare Source
What's Changed
streamable_http_clientwhich acceptshttpx.AsyncClientinstead ofhttpx_client_factoryby @Kludex in #1177New Contributors
Full Changelog: modelcontextprotocol/python-sdk@v1.23.3...v1.24.0
v1.23.3Compare Source
What's Changed
New Contributors
Full Changelog: modelcontextprotocol/python-sdk@v1.23.2...v1.23.3
v1.23.2Compare Source
What's Changed
New Contributors
Full Changelog: modelcontextprotocol/python-sdk@v1.23.1...v1.23.2
v1.23.1Compare Source
What's Changed
Full Changelog: modelcontextprotocol/python-sdk@v1.23.0...v1.23.1
v1.23.0Compare Source
Summary
This release brings us up to speed with the latest MCP spec
2025-11-25. Take a look at the latest spec as well as the release blog post.What's Changed
d3a1841)New Contributors
Full Changelog: modelcontextprotocol/python-sdk@v1.22.0...v1.23.0
v1.22.0Compare Source
What's Changed
ClientSessionGroup.call_tooland.connect_to_serverby @inaku-Gyan in #1576jsonschemalibrary by @wuliang229 in #1596New Contributors
Full Changelog: modelcontextprotocol/python-sdk@v1.21.1...v1.22.0
v1.21.2Compare Source
Hotfix Release
This is a hotfix release to address a critical bug in OAuth scope handling that caused failures on 401 responses.
Related:
What's Changed
New Contributors
Full Changelog: modelcontextprotocol/python-sdk@v1.21.1...v1.21.2
v1.21.1Compare Source
What's Changed
func_metadata()implementation by @Viicos in #1496New Contributors
Full Changelog: modelcontextprotocol/python-sdk@v1.21.0...v1.21.1
v1.21.0Compare Source
What's Changed
ClientSessionGroupdoc string by @inaku-Gyan in #1572New Contributors
Full Changelog: modelcontextprotocol/python-sdk@v1.20.0...v1.21.0
v1.20.0Compare Source
What's Changed
New Contributors
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.