CVE-2025-53365
Awaiting Analysis Awaiting Analysis - Queue
BaseFortify

Publication date: 2025-07-04

Last updated on: 2025-07-08

Assigner: GitHub, Inc.

Description
The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.10.0, if a client deliberately triggers an exception after establishing a streamable HTTP session, this can lead to an uncaught ClosedResourceError on the server side, causing the server to crash and requiring a restart to restore service. Impact may vary depending on the deployment conditions, and presence of infrastructure-level resilience measures. Version 1.10.0 contains a patch for the issue.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-07-04
Last Modified
2025-07-08
Generated
2026-05-07
AI Q&A
2025-07-05
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-248 An exception is thrown from a function, but it is not caught.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in the MCP Python SDK (mcp) before version 1.10.0. If a client deliberately triggers an exception after establishing a streamable HTTP session, it can cause an uncaught ClosedResourceError on the server side. This error causes the server to crash and requires a restart to restore service.


How can this vulnerability impact me? :

The vulnerability can cause the server running the MCP Python SDK to crash unexpectedly when a client triggers an exception after starting a streamable HTTP session. This results in service disruption until the server is restarted. The impact depends on deployment conditions and whether infrastructure-level resilience measures are in place.


What immediate steps should I take to mitigate this vulnerability?

Upgrade the MCP Python SDK to version 1.10.0 or later, as this version contains a patch that fixes the vulnerability causing the server crash.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart