PT-2025-28027 · Unknown · Mcp Python Sdk

CVE-2025-53366

·

Published

2025-07-04

·

Updated

2026-07-07

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: MCP Python SDK versions prior to 1.9.4
Description: A validation error in the MCP SDK can cause an unhandled exception when processing malformed requests, resulting in service unavailability until manually restarted. The impact may vary depending on the deployment conditions and the presence of infrastructure-level resilience measures.
Recommendations: For versions prior to 1.9.4, update to version 1.9.4 to fix the validation error and prevent service unavailability due to unhandled exceptions when processing malformed requests.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00094
CVE-2025-53366
GHSA-3QHF-M339-9G5V
OESA-2026-1151
PYSEC-2026-1616

Affected Products

Mcp Python Sdk