Количество 2
Количество 2
CVE-2026-59950
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-level way to restrict which origins could connect to applications that exposed that transport. This issue is fixed in version 1.28.1.
GHSA-vj7q-gjh5-988w
MCP Python SDK: WebSocket server transport does not support Host/Origin validation
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-59950 The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-level way to restrict which origins could connect to applications that exposed that transport. This issue is fixed in version 1.28.1. | CVSS3: 8.1 | 0% Низкий | около 1 месяца назад | |
GHSA-vj7q-gjh5-988w MCP Python SDK: WebSocket server transport does not support Host/Origin validation | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу