CVE-2026-59950
published 2026-07-15CVE-2026-59950: The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated…
PriorityP340high8.1CVSS 3.1
AVNACLPRNUIRSUCHIHAN
EPSS
0.23%
14.2th percentile
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-level way to restrict which origins could connect to applications that exposed that transport. This issue is fixed in version 1.28.1.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ciena | mcp | >= 0 < 1.28.1 | 1.28.1 |
| lfprojects | mcp_python_sdk | < 1.28.1 | 1.28.1 |
| modelcontextprotocol | python-sdk | < 1.28.1 | 1.28.1 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
nvdv4.07.6HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
MCP Python SDK: WebSocket server transport does not support Host/Origin validation
ghsa·2026-07-16
CVE-2026-59950 [HIGH] CWE-1385 MCP Python SDK: WebSocket server transport does not support Host/Origin validation
MCP Python SDK: WebSocket server transport does not support Host/Origin validation
### Summary
In affected versions, the deprecated WebSocket server transport (`mcp.server.websocket.websocket_server`) accepted the WebSocket handshake without applying any `Host` or `Origin` header validation. The `TransportSecuritySettings` mechanism that the SSE and Streamable HTTP transports use for this purpose was not wired into the WebSocket transport, so there was no SDK-level way to restrict which origins could connect.
### Am I affected?
Only if a developer's application server exposes `mcp.server.websocket.websocket_server`. This transport has never been part of the MCP specification, is marked deprecated, and is not reachable through `FastMCP` — a developer must have wired it into an ASGI applic
VulDB
modelcontextprotocol MCP up to 1.28.0 WebSocket Server input validation
vuldb·2026-07-15·CVSS 7.6
CVE-2026-59950 [HIGH] modelcontextprotocol MCP up to 1.28.0 WebSocket Server input validation
A vulnerability was found in modelcontextprotocol MCP up to 1.28.0. It has been classified as critical. This issue affects some unknown processing of the component WebSocket Server. This manipulation causes improper input validation.
This vulnerability is registered as CVE-2026-59950. Remote exploitation of the attack is possible. No exploit is available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/modelcontextprotocol/python-sdk/commit/777b8d06710c140e3606b0d4598e2aa48546c266https://github.com/modelcontextprotocol/python-sdk/pull/2992https://github.com/modelcontextprotocol/python-sdk/releases/tag/v1.28.1https://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-vj7q-gjh5-988w
2026-07-15
Published