{"data":{"id":"e8934b7b-929d-4958-807a-3e98328d1123","title":"GHSA-3qhf-m339-9g5v: MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS","summary":"A validation error in the MCP Python SDK can cause an unhandled exception when it processes malformed requests. The result is service unavailability, returning 500 errors until the server is manually restarted. Impact depends on deployment conditions and any infrastructure-level resilience measures in place.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-3qhf-m339-9g5v","publishedAt":"2025-07-04T22:06:49.000Z","cveId":"CVE-2025-53366","cweIds":["CWE-248"],"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":["mcp@< 1.9.4 (fixed: 1.9.4)"],"affectedPackageNames":["mcp"],"affectedPackageRefs":["pypi:mcp"],"affectedVendors":[],"affectedVendorsRaw":["MCP Python SDK","FastMCP Server"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.09309,"epssCheckedAt":"2026-10-10T04:57:14.151Z","kevDateAdded":null,"advisoryAliases":["GHSA-3qhf-m339-9g5v"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2025-07-04T22:06:49.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}