Skip to content

MCPA-2026-0034

highauth-missing

MCP Python SDK WebSocket server transport lacks Host/Origin validation (CVE-2026-59950)

The MCP Python SDK (PyPI: mcp) before 1.28.1: the deprecated WebSocket server transport (mcp.server.websocket.websocket_server) accepted the WebSocket handshake without any Host or Origin header validation — the TransportSecuritySettings mechanism used by the SSE and Streamable HTTP transports was not wired into it, enabling DNS-rebinding / cross-origin access to locally hosted servers. Fixed in 1.28.1.

Affected packages

EcosystemPackageAffected versions
pypimcp
>= 0, < 1.28.1

Identifiers

CVE-2026-59950GHSA-vj7q-gjh5-988wCWE-346CWE-1385

References

Timeline

  • Published: 2026-07-16

← All advisories