216.73.216.233

CVE-2025-53365

· Published 04/07/2025 22:15 · Modified 04/07/2025 22:15

Labels: CVE-2025-53365 2025-07-04CVE-2025-53365CWE-248[email protected]

Essential information

Published
04/07/2025 22:15
Modified
04/07/2025 22:15
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.10.0, if a client deliberately triggers an exception after establishing a streamable HTTP session, this can lead to an uncaught ClosedResourceError on the server side, causing the server to crash and requiring a restart to restore service. Impact may vary depending on the deployment conditions, and presence of infrastructure-level resilience measures. Version 1.10.0 contains a patch for the issue.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
* / mcp cpe:2.3:a:*:mcp:<1.10.0:*:*:*:*:*:*:*

References