Skip to content

Security: Update Starlette dependency to address vulnerabilities #1557

Description

@ColeMurray

Issue

The project currently uses Starlette >=0.27, which includes versions with known security vulnerabilities. The dependency should be updated to >=0.49.1 to address these issues.

Impact

  • Main project: pyproject.toml
  • Example servers:
    • examples/servers/simple-streamablehttp/pyproject.toml
    • examples/servers/simple-streamablehttp-stateless/pyproject.toml

Resolution

A pull request has been created to update the Starlette dependency across all affected files:

References

  • Updated version: Starlette 0.49.1
  • Minimum required version: >=0.49.1

Activity

  1. ColeMurray commented on Oct 31, 2025

    @ColeMurray
    ContributorAuthor

    @Kludex the vulnerable starlette version is pinned in the uv.lock and is causing downstream consumers to pull it in as a transitive dependency.

    Surely we aren't suggesting that everyone downstream of MCP should explicitly add the updated starlette version to resolve this since we're not willing to update the lock file, right?

    I agree with the non-pinned update in the pyproject.toml, but not updating the lock seems not ideal

  2. Kludex commented on Nov 1, 2025

    @Kludex
    Member

    What are you talking about?

    Who are the downstream consumers?


    Yeah, it's okay to update the lock. But that shouldn't matter anyway as well.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions