Skip to content

dup-check - #3664

Closed
KaiyiQuan wants to merge 4 commits into
modelcontextprotocol:mainfrom
KaiyiQuan:fix/3661-sse-validation-crash
Closed

KaiyiQuan wants to merge 4 commits into
modelcontextprotocol:mainfrom
KaiyiQuan:fix/3661-sse-validation-crash

Conversation

@KaiyiQuan

Copy link
Copy Markdown

dup check only

KaiyiQuan added 4 commits October 9, 2026 18:09
…rigin

When a request to /sse fails the transport-security checks (DNS-rebinding
protection: disallowed Host -> 421, disallowed Origin -> 403), connect_sse
sends the rejection response and then raises ValueError to signal the
caller that no SSE session was established. FastMCP.sse_app()'s handle_sse
had no handler for it, so the exception escaped the ASGI callable and
uvicorn crashed the whole server process -- one malformed request killed
every client (reported in modelcontextprotocol#3661 via ida-pro-mcp's idalib-mcp).

Catch ValueError in handle_sse: the rejection response has already been
sent to that one client, so just return. Also document connect_sse's
send-then-raise contract so future callers know to handle it.

Adds a regression test driving MCPServer.sse_app() with a disallowed Host
through the in-process ASGI bridge: 421 returned and no exception escapes.
32 server/security tests pass (1367 in tests/server/).
Copilot AI balanced review requested due to automatic review settings October 9, 2026 11:49

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@KaiyiQuan KaiyiQuan closed this Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants