GHSA-9h52-p55h-vw2f: Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default
- Identifiers
- CVE-2025-66416GHSA-9h52-p55h-vw2f
- Published
- Record updated
- Affected
- mcp < 1.23.0
- Fixed in
- 1.23.0
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.5%
Summary
The Model Context Protocol (MCP) Python SDK did not enable DNS rebinding protection by default for HTTP-based servers. A malicious website could exploit DNS rebinding to send requests to an unauthenticated HTTP MCP server running on localhost that was built with FastMCP using streamable HTTP or SSE transport and without TransportSecuritySettings, invoking its tools or accessing its resources on the user's behalf. Servers using stdio transport are not affected.
Mitigation
Fixed in 1.23.0: FastMCP() servers now enable DNS rebinding protection by default when host is 127.0.0.1 or localhost. Users with custom low-level configurations using StreamableHTTPSessionManager or SseServerTransport directly should explicitly configure TransportSecuritySettings when running an unauthenticated server on localhost.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- mcpPyPILLM dependency since 2024-11-20 · 61 tracked dependents
Coverage
News, research and other items that mention CVE-2025-66416.
- GHSA-rcfx-77hg-w2wv: FastMCP updated to MCP 1.23+ due to CVE-2025-66416GitHub Advisory Database · 2025-12-26
Topics
Related items
- LowAnthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection FlawsSimilar attack · The Hacker News
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading