{"data":{"id":"506526da-98e6-4d79-b4f9-8129a443be2b","title":"GHSA-9h52-p55h-vw2f: Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default","summary":"The Model Context Protocol (MCP) Python SDK did not enable DNS rebinding protection by default for HTTP-based servers. A malicious website could exploit DNS rebinding to send requests to an unauthenticated HTTP MCP server running on localhost that was built with FastMCP using streamable HTTP or SSE transport and without TransportSecuritySettings, invoking its tools or accessing its resources on the user's behalf. Servers using stdio transport are not affected.","solution":"Fixed in 1.23.0: FastMCP() servers now enable DNS rebinding protection by default when host is 127.0.0.1 or localhost. Users with custom low-level configurations using StreamableHTTPSessionManager or SseServerTransport directly should explicitly configure TransportSecuritySettings when running an unauthenticated server on localhost.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-9h52-p55h-vw2f","publishedAt":"2025-12-02T16:52:08.000Z","cveId":"CVE-2025-66416","cweIds":["CWE-350","CWE-1188"],"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["mcp@< 1.23.0 (fixed: 1.23.0)"],"affectedPackageNames":["mcp"],"affectedPackageRefs":["pypi:mcp"],"affectedVendors":[],"affectedVendorsRaw":["Model Context Protocol (MCP) Python SDK","FastMCP"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00512,"epssCheckedAt":"2026-10-10T04:57:17.021Z","kevDateAdded":null,"advisoryAliases":["GHSA-9h52-p55h-vw2f"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2025-12-02T16:52:08.000Z","capecIds":null,"crossRefCount":1,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}