HighVulnerability
GHSA-3qhf-m339-9g5v: MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS
- Identifiers
- CVE-2025-53366GHSA-3qhf-m339-9g5v
- Published
- Record updated
- Affected
- mcp < 1.9.4
- Fixed in
- 1.9.4
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 9.3%
Summary
A validation error in the MCP Python SDK can cause an unhandled exception when it processes malformed requests. The result is service unavailability, returning 500 errors until the server is manually restarted. Impact depends on deployment conditions and any infrastructure-level resilience measures in place.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- mcpPyPILLM dependency since 2024-11-20 · 61 tracked dependents
Topics
Related items
- HighHermes Agent - Pre-Authentication Disk ConsumptionSimilar attack · Tenable Research Advisories
- MediumHermes Agent - Pre-Authentication Memory ExhaustionSimilar attack · Tenable Research Advisories
- MediumGHSA-v36g-jcw9-x7cw: Pydantic AI: Excessive resource use when local web fetching converts nested HTMLSimilar attack · GitHub Advisory Database
- MediumGHSA-v2xh-2vp8-57h8: Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrlSimilar attack · GitHub Advisory Database
- MediumGHSA-fpf4-vwcp-v4hp: Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`Similar attack · GitHub Advisory Database