Source · DiggingBeagle record
MCP Python SDK deprecated WebSocket transport lacked Host and Origin validation
GitHub security advisory for CVE-2026-59950, affecting the deprecated MCP Python SDK WebSocket server transport before 1.28.1.
- Published
- Jul 7, 2026
- Accessed
- Sep 15, 2026
- Publisher
- Model Context Protocol Python SDK / GitHub Security Advisory
- Source type
- primary
- Version
- 2026-07-07
- Rights
- Public web source; citation and short excerpt/paraphrase only.
Each support, contradiction or context label applies to a cited Claim, not to a whole Case.
Source record
The deprecated WebSocket transport accepted handshakes without Host or Origin validation; the advisory says the transport was not part of the MCP specification and was not reachable through FastMCP.
Claim-level citations (3)
- supportsA deprecated MCP WebSocket transport trusted the browser origin: Version 1.28.1 is listed as the patched MCP Python SDK release for CVE-2026-59950.
Patched versions
- supportsA deprecated MCP WebSocket transport trusted the browser origin: The advisory says the affected WebSocket transport was deprecated, not part of the MCP specification and not reachable through FastMCP; stdio, SSE and Streamable HTTP were not affected by this advisory.
Am I affected?
- supportsA deprecated MCP WebSocket transport trusted the browser origin: Before 1.28.1, the MCP Python SDK deprecated WebSocket server transport accepted handshakes without Host or Origin validation.
Summary
Cite this record
DiggingBeagle. “MCP Python SDK deprecated WebSocket transport lacked Host and Origin validation.” Published Jul 7, 2026 · Accessed Sep 15, 2026. https://diggingbeagle.com/sources/mcp-python-sdk-deprecated-websocket-transport-lacked-host-and-origin-validation/
Citation guidance