The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-level way to restrict which origins could connect to applications that exposed that transport. This issue is fixed in version 1.28.1.

Project Subscriptions

Vendors Products
Lfprojects Subscribe
Mcp Python Sdk Subscribe
Modelcontextprotocol Subscribe
Python-sdk Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-vj7q-gjh5-988w MCP Python SDK: WebSocket server transport does not support Host/Origin validation
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 17 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Modelcontextprotocol
Modelcontextprotocol python-sdk
Vendors & Products Modelcontextprotocol
Modelcontextprotocol python-sdk

Wed, 15 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-level way to restrict which origins could connect to applications that exposed that transport. This issue is fixed in version 1.28.1.
Title MCP Python SDK: WebSocket server transport does not support Host/Origin validation
Weaknesses CWE-1385
CWE-346
References
Metrics cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-17T12:28:19.431Z

Reserved: 2026-07-07T18:49:15.607Z

Link: CVE-2026-59950

cve-icon Vulnrichment

Updated: 2026-07-17T12:28:16.145Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-15T21:16:55.683

Modified: 2026-07-17T18:07:38.087

Link: CVE-2026-59950

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:00:06Z

Weaknesses