CVE-2026-0621Patch(lfprojects / mcp_typescript_sdk)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch lfprojects mcp_typescript_sdk systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS) vulnerability in the UriTemplate class when processing RFC 6570 exploded array patterns. The dynamically generated regular expression used during URI matching contains nested quantifiers that can trigger catastrophic backtracking on specially crafted inputs, resulting in excessive CPU consumption. An attacker can exploit this by supplying a malicious URI that causes the Node.js process to become unresponsive, leading to a denial of service.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1333

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mcp_typescript_sdk

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 3 signals
  • Peaked 2d ago at 2 mentions (2026-01-29); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
mcp_typescript_sdk

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-01-29: 2Mentions · 2026-02-02: 1Mentions · 2026-06-01: 1Patch / Workaround · 2026-01-29: 2Patch / Workaround · 2026-02-02: 1Patch / Workaround · 2026-06-01: 1Technical Details · 2026-01-29: 2Technical Details · 2026-02-02: 101-2902-0206-01
Signal classification1 categories
Patch
4100.0%
Classification over time
DateTotalLabels
2026-01-292
Patch2
2026-02-021
Patch1
2026-06-011
Patch1
Full discourse4 posts
  • Jeremy McHugh, DSc.@jer_mchugh
    Patch

    If you're building with MCP, here's what you need to know this week: CVE-2026-0621 dropped. A single malicious URI can freeze your MCP server. Fix is simple: upgrade to v1.25.2. Let's talk about what's actually happening and how to ship secure MCP code.

    Post summary

    The post announces CVE-2026-0621, a denial‑of‑service flaw where a single malicious URI can freeze an MCP server, and advises upgrading to v1.25.2 to remediate the issue.

    1002082
    412 followersView on X
  • MX3 Dev@Mx3Dev
    Patch

    @mem0ai Dependency hardening → Pinned jws to 4.0.1 (CVE-2025-65945) → Pinned tar-fs to ^2.1.4 (CVE-2025-48387, CVE-2025-59343) → Pinned @modelcontextprotocol/sdk to ^1.25.4 (CVE-2025-66414, CVE-2026-0621) → Pinned rollup to ^4.59.0 (CVE-2026-27606)

    Post summary

    The post enumerates several CVE IDs and shows the organization mitigates them by pinning dependencies to fixed, non‑vulnerable versions.

    1000054
    106 followersView on X
  • transilienceai@transilienceai
    Patch

    @ecap0_ Separate issues exist, e.g., ReDoS (CVE-2026-0621) in MCP TypeScript SDK affecting servers with exploded URI templates. Anthropic fixed quietly without public response to inquiries; no evidence of widespread exploitation reported. #SecurityAwareness 🔍

    Post summary

    ReDoS vulnerability CVE-2026-0621 in the MCP TypeScript SDK was identified; Anthropic quietly patched the issue with no reported widespread exploitation.

    1000040
    317 followersView on X
  • Jeremy McHugh, DSc.@jer_mchugh
    Patch

    2/ This week: CVE-2026-0621 ReDoS in the MCP TypeScript SDK's UriTemplate class. A crafted URI triggers catastrophic regex backtracking, event loop blocked, server down. Fix: Upgrade to v1.25.2. Takes 2 minutes.

    Post summary

    The post reports a ReDoS vulnerability in the MCP TypeScript SDK that can bring servers down and recommends a quick upgrade to v1.25.2.

    1000054
    412 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applfprojectsmcp_typescript_sdk---

Explore more