CVE-2026-52869
- EPSS 0.32%
- Veröffentlicht 15.07.2026 20:17:38
- Zuletzt bearbeitet 17.07.2026 18:06:50
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.Streamab...
CVE-2026-52870
- EPSS 0.24%
- Veröffentlicht 15.07.2026 20:17:38
- Zuletzt bearbeitet 17.07.2026 18:07:07
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/canc...
CVE-2026-59950
- EPSS 0.15%
- Veröffentlicht 15.07.2026 20:08:54
- Zuletzt bearbeitet 17.07.2026 18:07:38
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin head...
CVE-2025-66416
- EPSS 0.52%
- Veröffentlicht 02.12.2025 18:14:28
- Zuletzt bearbeitet 10.03.2026 19:40:36
The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.23.0, tThe Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default for HTTP-based servers...