VulnSea

mcp has 12 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 9 in the last 90 days against 0 in the 90 before. The busiest recent month was July 2026 with 8. The median CVSS is 7.1 (high). None have a confirmed exploitation report. The most common weakness class is CWE-770 (4). Most affected products: mcp (11), mcp/sdk (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.1
Publish → KEV
Last 90 days
9 prev 0

Products

  • mcp 11
  • mcp/sdk 1
12
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

mcp vulnerabilities

CVEs affecting mcp, newest first. Open any entry for full detail, references, and exploit status.

12 CVEsRSS

CVE-2026-53965High
3w ago

The MCP PHP SDK (Composer package mcp/sdk) is the official Model Context Protocol SDK for PHP

The MCP PHP SDK (Composer package mcp/sdk) is the official Model Context Protocol SDK for PHP. In versions 0.5.0 through 0.7.0, the HTTP client transport reads a Server-Sent Events response stream incrementally and appends each chunk to …

Twilightmcp · mcp/sdkEPSS 0.36%via NVD
CVE-2026-63118Medium
1mo ago

MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection

MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection

Sunlitmcp · mcpEPSS 0.19%via GHSA
CVE-2026-63119Medium· 6.2
1mo ago

MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)

MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)

Sunlitmcp · mcpEPSS 0.13%via GHSA
CVE-2026-67430Medium· 5.3
1mo ago

MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood

MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood

Sunlitmcp · mcpEPSS 0.31%via GHSA
CVE-2026-67432High· 7.5
1mo ago

MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport

MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport

Twilightmcp · mcpEPSS 0.43%via GHSA
CVE-2026-67431High
1mo ago

MCP Ruby SDK: Ruby SSE Session Poisoning

MCP Ruby SDK: Ruby SSE Session Poisoning

Twilightmcp · mcpEPSS 0.29%via GHSA
CVE-2026-52869High· 7.1
2mo ago

MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal

MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal

Twilightmcp · mcpEPSS 0.53%via OSV
CVE-2026-59950High
2mo ago

MCP Python SDK: WebSocket server transport does not support Host/Origin validation

MCP Python SDK: WebSocket server transport does not support Host/Origin validation

Twilightmcp · mcpEPSS 0.23%via OSV
CVE-2026-52870High· 7.6
2mo ago

MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks

MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks

Twilightmcp · mcpEPSS 0.39%via OSV
CVE-2025-66416High
9mo ago

Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default

Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default

Twilightmcp · mcpEPSS 0.51%via OSV
CVE-2025-53365High
1y ago

MCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service

MCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service

Twilightmcp · mcpEPSS 0.37%via OSV
CVE-2025-53366High
1y ago

MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS

MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS

Twilightmcp · mcpEPSS 7.3%via OSV
mcp vulnerabilities (CVEs) · VulnSea