pkg:PyPI/mcp
6 total CVEsHIGH2
✅ Check your installed version
All known vulnerabilities
HIGH7.6CVE-2026-52870MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks >= 1.23.0, < 1.27.2
HIGH7.1CVE-2026-52869MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal from 0, < 1.27.2
—CVE-2026-59950MCP Python SDK: WebSocket server transport does not support Host/Origin validation from 0, < 1.28.1
—CVE-2025-66416Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default from 0, < 1.23.0
—MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS
from 0, < 1.9.4
—MCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service
from 0, < 1.10.0