CVE-2025-53366
MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS
EPSS 5.7%
描述
A validation error in the MCP SDK can cause an unhandled exception when processing malformed requests, resulting in service unavailability (500 errors) until manually restarted. Impact may vary depending on the deployment conditions, and presence of infrastructure-level resilience measures. Thank you to Rich Harang for reporting this issue.
如何修補 CVE-2025-53366
要修補 CVE-2025-53366,請將受影響套件升級到下列已修補版本。
- PyPI/mcp—升級至 1.9.4 或更新版本
CVE-2025-53366 正在被利用嗎?
中等 — EPSS 為 5.7%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 1.9.4
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |