CVE-2025-53365High▾ TwilightMCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
0.4% → 0.4%
If a client deliberately triggers an exception after establishing a streamable HTTP session, this can lead to an uncaught ClosedResourceError on the server side, causing the server to crash and requiring a restart to restore service. Impact may vary depending on the deployment conditions, and presence of infrastructure-level resilience measures.
Thank you to Rich Harang for reporting this issue.
mcp < 1.10.0Upgrade to a patched release:
mcp 1.10.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-52869High· 7.1MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
CVE-2026-59950HighMCP Python SDK: WebSocket server transport does not support Host/Origin validation
CVE-2026-52870High· 7.6MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
CVE-2025-66416HighModel Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default
CVE-2025-53366HighMCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS
CVE-2026-94044High· 7.3A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546