CVE-2026-25536
From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reused across multiple client connections, most commonly in stateless StreamableHTTPServerTransport deployments.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reused across multiple client connections, most commonly in stateless StreamableHTTPServerTransport deployments. This issue has been patched in version 1.26.0.
- CVSS 3.1
- 7.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- EPSS
- 0.28% probability · 20th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362, CWE-367
- Affected
- lfprojects/mcp typescript sdk
- Source
- security-advisories@github.com
References
- https://github.com/modelcontextprotocol/typescript-sdk/issues/204Issue Tracking, Vendor Advisory
- https://github.com/modelcontextprotocol/typescript-sdk/issues/243Issue Tracking, Vendor Advisory
- https://github.com/modelcontextprotocol/typescript-sdk/security/advisories/GHSA-345p-7cg4-v4c7Mitigation, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:3960
- https://access.redhat.com/security/cve/CVE-2026-25536
- https://bugzilla.redhat.com/show_bug.cgi?id=2436937
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25536.json
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.