CVE-2026-25536

MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reused across multiple client connections, most commonly in stateless StreamableHTTPServerTransport deployments. This issue has been patched in version 1.26.0.
Configurations

No configuration.

History

04 Feb 2026, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-04 22:15

Updated : 2026-02-05 14:57


NVD link : CVE-2026-25536

Mitre link : CVE-2026-25536

CVE.ORG link : CVE-2026-25536


JSON object : View

Products Affected

No product.

CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')