CVE-2025-66416
HighAdvisory
Published 2 Dec 2025In the index since 8 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.6
- base score, highest
- EPSS
- 0.005
- 42nd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 6
- of 17,781 indexed, latest versions
- Container images
- 6
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default
Carried by container images the latest versions of 6 of 17,781 indexed charts deploy, on 6 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| mcppypi | 1.1.2, 1.8.1, 1.9.4, 1.10.1+1 more | 1.23.0 | 6 |
- OSV records
- GHSA-9h52-p55h-vw2f
- Also known as
- PYSEC-2026-1617
Charts affected
6 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| litellmlitellm-helm | 0.2.0 | 1 of 1See more | 4,292 |
| csghubcsghubVerified publisher | 2.4.3 | 1 of 34See more | 58,897 |
| csgshipcsghubVerified publisher | 0.4.6 | 1 of 10See more | 11,335 |
| home-assistanthelm-chart-roeiVerified publisher | 2025.3.0 | 1 of 1See more | 4,647 |
| graphiti-mcpkiberonlabs | 0.1.2 | 1 of 1See more | 3,393 |
| home-assistantpascaliskeVerified publisher | 0.1.1 | 1 of 1See more | 4,749 |
Container images carrying it
6 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| opencsghq/ | 2f03fead54db | mcp | 1.23.0 | 1 |
| opencsghq/ | 2cd29671a03e | mcp | 1.23.0 | 1 |
| zepai/ | 6ab0ee79926b | mcp | 1.23.0 | 1 |
| ghcr.io/ | ab63d26a8a2c | mcp | 1.23.0 | 1 |
| ghcr.io/ | 26c51e44d932 | mcp | 1.23.0 | 1 |
| ghcr.io/ | 9a5a3eb4a213 | mcp | 1.23.0 | 1 |