CVE-2026-52869
published 2026-07-15CVE-2026-52869: The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP…
PriorityP341high7.1CVSS 3.1
AVNACHPRLUINSUCHIHAL
EPSS
0.53%
44.1th percentile
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.StreamableHTTPSessionManager route requests to existing sessions using only the session_id query parameter or Mcp-Session-Id header without verifying the authenticated principal that created the session, allowing a different bearer-token-authenticated client with a known session ID to inject JSON-RPC messages into that session. This issue is fixed in version 1.27.2.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ciena | mcp | >= 0 < 1.27.2 | 1.27.2 |
| lfprojects | mcp_python_sdk | < 1.27.2 | 1.27.2 |
| modelcontextprotocol | python-sdk | < 1.27.2 | 1.27.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
ghsa·2026-07-16
CVE-2026-52869 [HIGH] CWE-639 MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
### Summary
In affected versions, the SSE and Streamable HTTP server transports routed incoming requests to an existing session based only on the session identifier, without verifying that the request was authenticated as the same principal that created the session. Anyone who learned or guessed a session ID could send JSON-RPC messages on that session, regardless of which bearer token the request carried.
### Am I affected?
Only if a developer's application server uses an HTTP transport (SSE, or Streamable HTTP in stateful mode) **and** authenticates requests. Servers on stdio, stateless Streamable HTTP, or with no authentication configured are not affected.
### Details
Both transports
VulDB
modelcontextprotocol python-sdk up to 1.27.1 SSE Transport/Streamable HTTP Transport server.sse session_id/Mcp-Session-Id injection
vuldb·2026-07-15·CVSS 7.1
CVE-2026-52869 [HIGH] modelcontextprotocol python-sdk up to 1.27.1 SSE Transport/Streamable HTTP Transport server.sse session_id/Mcp-Session-Id injection
A vulnerability marked as critical has been reported in modelcontextprotocol python-sdk up to 1.27.1. The impacted element is an unknown function of the file server.sse of the component SSE Transport/Streamable HTTP Transport. The manipulation of the argument session_id/Mcp-Session-Id leads to injection.
This vulnerability is uniquely identified as CVE-2026-52869. The attack is possible to be carried out remotely. No exploit exists.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/modelcontextprotocol/python-sdk/commit/1abcca2408a6b50e10ec601181f63f9978705c00https://github.com/modelcontextprotocol/python-sdk/commit/ce267b6fc515dc4efc1dc70b6975b16ff0feef0ahttps://github.com/modelcontextprotocol/python-sdk/pull/2690https://github.com/modelcontextprotocol/python-sdk/pull/2719https://github.com/modelcontextprotocol/python-sdk/releases/tag/v1.27.2https://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-jpw9-pfvf-9f58
2026-07-15
Published