Skip to content
HighVulnerability

GHSA-3qhf-m339-9g5v: MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS

Published
Record updated
View JSON
Affected
  • mcp < 1.9.4
Fixed in
1.9.4
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
9.3%

Summary

A validation error in the MCP Python SDK can cause an unhandled exception when it processes malformed requests. The result is service unavailability, returning 500 errors until the server is manually restarted. Impact depends on deployment conditions and any infrastructure-level resilience measures in place.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.