CVE-2026-32871·Python vulnerability
FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is responsible for constructing HTTP requests to the backend service. A vulnerability exists in the _build_url() method. When an OpenAPI operation defines path parameters (e.g., /api/v1/users/{user_id}), the system directly substitutes parameter values into the URL template string without URL-encoding. Subsequently, urllib.parse.urljoin() resolves the final URL. Since urljoin() interprets ../ sequences as directory traversal, an attacker controlling a path parameter can perform path traversal attacks to escape the intended API prefix and access arbitrary backend endpoints. This results in authenticated SSRF, as requests are sent with the authorization headers configured in the MCP provider. This issue has been patched in version 3.2.0.
- Severity
- critical
- Software
- Python
- Fixed in
- 3.2.0
- Published
- 2026-04-02
Affected versions
Until: 3.2.0
Fixed in: 3.2.0
How to fix this CVE
Upgrade FastMCP to version 3.2.0 or later to remediate a critical path traversal vulnerability in the OpenAPIProvider component. The vulnerability allows attackers to bypass URL path validation by injecting directory traversal sequences into OpenAPI path parameters, enabling unauthorized access to backend services. Update your Python environment immediately and verify the patch is applied.
sudo dnf update python3-fastmcp || sudo pip3 install --upgrade fastmcp>=3.2.0Defensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
GET|POST|PUT|DELETE /api/.*/\.\./ HTTP/1.1|Authorization: Bearer|X-Authorization|Referer: (http|https)://[a-zA-Z0-9.-]+/api/|Remote path traversal attempt detected in OpenAPI path parameterWAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement a WAF rule to block HTTP requests containing unencoded '../' or '%2e%2e%2f' sequences in URL paths targeting OpenAPI endpoints. Additionally, enforce strict URL validation to reject requests where path parameters contain directory traversal patterns before they reach the backend service.How to check if you are affected
- Run 'python3 -c "import fastmcp; print(fastmcp.__version__)"' to check the installed FastMCP version; vulnerable versions are below 3.2.0
- Search your codebase for OpenAPIProvider instantiation: grep -r "OpenAPIProvider" . to identify if this component is actively used
- Check application logs for HTTP requests containing '../' sequences in path parameters targeting OpenAPI endpoints, indicating exploitation attempts
- After patching, re-run the version check command and confirm the output is 3.2.0 or higher
FAQ
What is CVE-2026-32871?
CVE-2026-32871 is a critical path traversal vulnerability in FastMCP's OpenAPIProvider that fails to URL-encode path parameters before substituting them into URL templates. Attackers can inject '../' sequences to escape the intended API prefix and access arbitrary backend endpoints with authenticated credentials.
Is CVE-2026-32871 being actively exploited?
No, this vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, and no public exploits are publicly available at this time.
What versions of FastMCP are affected by CVE-2026-32871?
All versions of FastMCP prior to version 3.2.0 are affected; version 3.2.0 and later contain the security patch.
How do I check if my server is vulnerable to CVE-2026-32871?
Run 'python3 -c "import fastmcp; print(fastmcp.__version__)"' to display the installed version. If the output is below 3.2.0, your installation is vulnerable.
Does Defensia detect CVE-2026-32871?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If FastMCP is installed on a monitored server, CVE-2026-32871 will appear in your dashboard with remediation steps.
Related Python CVEs
References
- https://github.com/PrefectHQ/fastmcp/commit/40bdfb6b1de0ce30609ee9ba5bb95ecd04a9fb71
- https://github.com/PrefectHQ/fastmcp/pull/3507
- https://github.com/PrefectHQ/fastmcp/releases/tag/v3.2.0
- https://github.com/PrefectHQ/fastmcp/security/advisories/GHSA-vv7q-7jx5-f767
- https://access.redhat.com/errata/RHSA-2026:36350
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-32871. Free for 1 server.
Get started free