GHSA-8r9q-7v3j-jr4g

Suggest an improvement
Source
https://github.com/advisories/GHSA-8r9q-7v3j-jr4g
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-8r9q-7v3j-jr4g/GHSA-8r9q-7v3j-jr4g.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-8r9q-7v3j-jr4g
Aliases
Downstream
CGA (31)
MINI (5)
Published
2026-01-05T21:30:33Z
Modified
2026-07-17T21:06:39Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Details

Impact

A ReDoS vulnerability in the UriTemplate class allows attackers to cause denial of service. The partToRegExp() function generates a regex pattern with nested quantifiers (([^/]+(?:,[^/]+)*)) for exploded template variables (e.g., {/id*}, {?tags*}), causing catastrophic backtracking on malicious input.

Who is affected: MCP servers that register resource templates with exploded array patterns and accept requests from untrusted clients.

Attack result: An attacker sends a crafted URI via resources/read request, causing 100% CPU utilization, server hang/crash, and denial of service for all clients.

Affected Versions

All versions of @modelcontextprotocol/sdk prior to the patched release.

Patches

v1.25.2 contains b392f02ffcf37c088dbd114fedf25026ec3913d3 the fix modifies the regex pattern to prevent backtracking.

Workarounds

  • Avoid using exploded patterns ({/id*}, {?tags*}) in resource templates
  • Implement request timeouts and rate limiting
  • Validate URIs before processing to reject suspicious patterns
Database specific
{
    "cwe_ids": [
        "CWE-1333"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-01-06T21:20:37Z",
    "nvd_published_at": "2026-01-05T21:16:14Z",
    "severity": "HIGH"
}
References

Affected packages

npm / @modelcontextprotocol/sdk

Package

Name
@modelcontextprotocol/sdk
View open source insights on deps.dev
Purl
pkg:npm/%40modelcontextprotocol/sdk

Affected ranges

Type
SEMVER
Events
Introduced
1.3.0
Fixed
1.25.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-8r9q-7v3j-jr4g/GHSA-8r9q-7v3j-jr4g.json"