CVE-2025-53366High▾ TwilightMCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 1.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
5.7%
5.7% → 7.3%
A validation error in the MCP SDK can cause an unhandled exception when processing malformed requests, resulting in service unavailability (500 errors) until manually restarted. Impact may vary depending on the deployment conditions, and presence of infrastructure-level resilience measures.
Thank you to Rich Harang for reporting this issue.
mcp < 1.9.4Upgrade to a patched release:
mcp 1.9.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-52869High· 7.1MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
CVE-2026-59950HighMCP Python SDK: WebSocket server transport does not support Host/Origin validation
CVE-2026-52870High· 7.6MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
CVE-2025-53365HighMCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service
CVE-2025-66416HighModel Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default
CVE-2026-94044High· 7.3A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546