High severityNVD Advisory· Published Jul 15, 2026· Updated Jul 16, 2026
MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
CVE-2026-52869
Description
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.StreamableHTTPSessionManager route requests to existing sessions using only the session_id query parameter or Mcp-Session-Id header without verifying the authenticated principal that created the session, allowing a different bearer-token-authenticated client with a known session ID to inject JSON-RPC messages into that session. This issue is fixed in version 1.27.2.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mcpPyPI | < 1.27.2 | 1.27.2 |
Affected products
4- Range: <1.27.2
- osv-coords3 versions
< 1.93.0-r0+ 2 more
- (no CPE)range: < 1.93.0-r0
- (no CPE)range: < 1.172.0-r1
- (no CPE)range: < 1.172.0-r1
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-jpw9-pfvf-9f58ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-52869ghsaADVISORY
- github.com/modelcontextprotocol/python-sdk/commit/1abcca2408a6b50e10ec601181f63f9978705c00ghsax_refsource_MISCWEB
- github.com/modelcontextprotocol/python-sdk/commit/ce267b6fc515dc4efc1dc70b6975b16ff0feef0aghsax_refsource_MISCWEB
- github.com/modelcontextprotocol/python-sdk/pull/2690ghsax_refsource_MISCWEB
- github.com/modelcontextprotocol/python-sdk/pull/2719ghsax_refsource_MISCWEB
- github.com/modelcontextprotocol/python-sdk/releases/tag/v1.27.2ghsax_refsource_MISCWEB
- github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-jpw9-pfvf-9f58ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.