PT-2025-28027 · Unknown · Mcp Python Sdk

Published

2025-07-04

·

Updated

2026-01-22

·

CVE-2025-53366

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: MCP Python SDK versions prior to 1.9.4
Description: A validation error in the MCP SDK can cause an unhandled exception when processing malformed requests, resulting in service unavailability until manually restarted. The impact may vary depending on the deployment conditions and the presence of infrastructure-level resilience measures.
Recommendations: For versions prior to 1.9.4, update to version 1.9.4 to fix the validation error and prevent service unavailability due to unhandled exceptions when processing malformed requests.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

BDU:2026-00094
CVE-2025-53366
GHSA-3QHF-M339-9G5V

Affected Products

Mcp Python Sdk