CVE-2026-59950CWE-1385CWE-346

MCP Python SDK: WebSocket server transport does not support Host/Origin validation

High · published July 15, 2026

CVSS v4.0
7.6
EPSS
0%
Percentile
13.8
In the wild
Unconfirmed
What it is

The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-level way to restrict which origins could connect to applications that exposed that transport. This issue is fixed in version 1.28.1.

The record
Technical detail
CVSS v4.0
7.6 · HIGH
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS
0.00231 · 13.8th percentile
Weaknesses
CWE-1385 · Missing Origin Validation in WebSockets; CWE-346 · Origin Validation Error
Published
2026-07-15T20:08Z
EPSS history
Timeline
  • 15 JUL 20:08Z
    MCP Python SDK: WebSocket server transport does not support Host/Origin validation
    cvelistv5