HighVulnerability
GHSA-j975-95f5-7wqh: MCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service
- Identifiers
- CVE-2025-53365GHSA-j975-95f5-7wqh
- Published
- Record updated
- Affected
- mcp < 1.10.0
- Fixed in
- 1.10.0
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.4%
Summary
The MCP Python SDK's streamable HTTP transport has an unhandled exception. A client that deliberately triggers an exception after establishing a streamable HTTP session can cause an uncaught ClosedResourceError on the server. The server then crashes and needs a restart to restore service. Impact depends on deployment conditions and any infrastructure-level resilience measures.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- mcpPyPILLM dependency since 2024-11-20 · 61 tracked dependents
Topics
Related items
- HighHermes Agent - Pre-Authentication Disk ConsumptionSimilar attack · Tenable Research Advisories
- MediumHermes Agent - Pre-Authentication Memory ExhaustionSimilar attack · Tenable Research Advisories
- MediumGHSA-v36g-jcw9-x7cw: Pydantic AI: Excessive resource use when local web fetching converts nested HTMLSimilar attack · GitHub Advisory Database
- MediumGHSA-v2xh-2vp8-57h8: Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrlSimilar attack · GitHub Advisory Database
- MediumGHSA-fpf4-vwcp-v4hp: Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`Similar attack · GitHub Advisory Database