{"data":{"id":"926d47ed-94ab-4ad5-b21c-d6ce039915f5","title":"GHSA-vj7q-gjh5-988w: MCP Python SDK: WebSocket server transport does not support Host/Origin validation","summary":"The deprecated WebSocket server transport, mcp.server.websocket.websocket_server, in the MCP Python SDK accepted WebSocket handshakes without validating the Host or Origin headers, because TransportSecuritySettings was never wired into it. A malicious web page can open a connection to an exposed server on this transport, complete initialize, and invoke its tools and read its resources, and the transport requires no token or prior session. Only applications that wire this transport into their own ASGI server are affected.","solution":"Upgrade to version 1.28.1 or later, which adds the optional security_settings: TransportSecuritySettings argument and validates Host and Origin headers, rejecting failed requests with HTTP 403 and ValueError(\"Request validation failed\"). The parameter defaults to None, which leaves validation disabled, so pass a TransportSecuritySettings with enable_dns_rebinding_protection=True and appropriate allowed_hosts / allowed_origins. The recommended path is to migrate to Streamable HTTP, where FastMCP enables this protection automatically for localhost binds. The WebSocket transport has been removed entirely in v2.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-vj7q-gjh5-988w","publishedAt":"2026-07-16T20:14:34.000Z","cveId":"CVE-2026-59950","cweIds":["CWE-346","CWE-1385"],"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["mcp@< 1.28.1 (fixed: 1.28.1)"],"affectedPackageNames":["mcp"],"affectedVendors":[],"affectedVendorsRaw":["MCP Python SDK","FastMCP"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00231,"epssCheckedAt":"2026-10-10T04:57:25.795Z","kevDateAdded":null,"advisoryAliases":["GHSA-vj7q-gjh5-988w"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-07-16T20:14:34.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}