Vulnerability GHSA-8r9q-7v3j-jr4g

High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
9 months ago
January 05, 2026 at 09:30 PM UTC
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
1.3.0 - 1.25.1
1.3.0 - 1.25.1

Summary

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

Details

Impact

A ReDoS vulnerability in the UriTemplate class allows attackers to cause denial of service. The partToRegExp() function generates a regex pattern with nested quantifiers (([^/]+(?:,[^/]+)*)) for exploded template variables (e.g., {/id*}, {?tags*}), causing catastrophic backtracking on malicious input.

Who is affected: MCP servers that register resource templates with exploded array patterns and accept requests from untrusted clients.

Attack result: An attacker sends a crafted URI via resources/read request, causing 100% CPU utilization, server hang/crash, and denial of service for all clients.

Affected Versions

All versions of @modelcontextprotocol/sdk prior to the patched release.

Patches

v1.25.2 contains b392f02ffcf37c088dbd114fedf25026ec3913d3 the fix modifies the regex pattern to prevent backtracking.

Workarounds

  • Avoid using exploded patterns ({/id*}, {?tags*}) in resource templates
  • Implement request timeouts and rate limiting
  • Validate URIs before processing to reject suspicious patterns

Impacted packages

Timeline

Published
9 months ago
January 05, 2026 at 09:30 PM UTC
Fixed (1.25.2)
9 months ago
January 07, 2026 at 03:34 PM UTC
Last Modified
26 days ago
September 10, 2026 at 03:50 AM UTC