MCP Python SDK leaks OAuth credentials to servers


Model Context Protocol Python SDK versions 1.9.1–1.29.1 and 2.0.0–2.1.1 send OAuth credentials to attacker-controlled endpoints. The SDK trusts MCP servers' authorization URLs without validating them against expected issuers. Cycode demonstrated full token exchange; stolen credentials remain valid until rotated. CVSS scores range from 6.5 to 7.5 depending on flow type.

Teams must upgrade to 1.30.0 or 2.2.0 and add `issuer=` parameters to credential providers. Meanwhile, ShinyHunters breached the FBI jobs site immediately after Dutch police arrested a member, exploiting an Oracle PeopleSoft zero-day despite law enforcement pressure.

In this issue:

  • MCP Python SDK OAuth leak: versions 1.9.1–2.1.1 affected
  • ShinyHunters exploits CVE-2026-35273 in PeopleSoft after member arrest
  • GCP Z4D instances: 5th Gen EPYC with 84TB local SSD
  • Cloudflare BEACON: billions of real-user performance measurements in BigQuery

MCP Python SDK Flaw Leaks OAuth Credentials to Malicious Servers

The Signal

Model Context Protocol Python SDK before 1.30.0 and 2.2.0 sends OAuth secrets to attacker-controlled token endpoints.

What Changed

  • Versions 1.9.1–1.29.1 and 2.0.0–2.1.1 send client secrets, auth codes, and PKCE keys to malicious servers.
  • SDK trusts MCP server's authorization server URL without validation against expected issuer.
  • Cycode demonstrated full token exchange; stolen credentials remain valid until rotated.
  • CVSS 7.5 for non-interactive providers, 6.5 for interactive OAuth flows.
  • Fixed versions reject token endpoints that don't match declared issuer: https://cycode.com/blog/mcp-python-sdk-flaw/

Operational Impact

Teams running MCP clients with OAuth over HTTP must upgrade immediately and rotate all client secrets. ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider require adding the `issuer=` parameter after upgrade—without it, the fix doesn't activate. Clear stored OAuth registrations once post-upgrade. Audit logs for connections to untrusted MCP servers during the vulnerable window from version 1.9.1 release through September 7.

Watch For

No CVE assigned as of September 29. Check whether credentials were exposed during the multi-month window before the September 7 fix shipped.


ShinyHunters Breaches FBI Site After Dutch Arrest

The Signal

Dutch police arrested Pepijn van der Stap (23) for ShinyHunters activity; group immediately breached FBI jobs site.

What Changed

  • Van der Stap previously convicted for €1.5-2.7M in data thefts under handle Umbreon.
  • ShinyHunters exploited CVE-2026-35273 in Oracle PeopleSoft as zero-day since June 2026.
  • Group mass-exploited dozens of orgs across education, healthcare, government, and tech sectors.
  • FBI breach exposed 5,000+ SSNs, psychiatric files, and team assignments via apply.fbijobs.gov.
  • Attackers used URL-encoding to bypass Mandiant's published WAF mitigation rules.

Operational Impact

Teams running PeopleSoft must verify Oracle's September patch is applied and review WAF rules for encoding bypass vectors. The breach demonstrates that initial vendor mitigations may be insufficient and that threat groups maintain operational capacity during law enforcement actions. Organizations using PeopleSoft for HR or hiring workflows should audit access logs for June-September 2026 and rotate credentials for any potentially compromised systems.

Watch For

ShinyHunters escalated to direct law enforcement targeting after the arrest, signaling a shift toward higher-risk retaliation. Mandiant estimates the group is tracking toward $100M in 2026 extortion revenue despite increased law enforcement pressure.


GCP Z4D: 5th Gen EPYC Storage Instances with 84TB Local SSD

The Signal

Google launched Z4D VMs with 5th Gen AMD EPYC Turin and up to 84TB Local SSD.

What Changed

  • Two VM types: Z4D-highmem-standardlssd at 219 GiB LSSD per vCPU, Z4D-highmem-highlssd at 438 GiB per vCPU.
  • Delivers 15,600K random read IOPS and 75.6 GiB/s sequential read throughput via Titanium SSDs.
  • 40% performance gain over Z3; 70% faster local SSD, 25% lower write latency. https://cloud.google.com/blog/products/compute/storage-optimized-z4d-vm-and-bare-metal-instances
  • Bare metal instances support custom hypervisors and Nutanix Cloud Clusters; Z4D VMs in preview.
  • Up to 384 vCPUs, 3TB memory, and 400 Gbps networking per instance.

Operational Impact

Teams running MySQL, Postgres, or OLAP should evaluate standardlssd shapes. Distributed databases and streaming workloads fit highlssd instances with double the LSSD density. Z4D scales with existing Z3 clusters, but VMs above 42TB LSSD require maintenance restarts instead of live migration. Bare metal suits latency-sensitive workloads and custom licensing models.

Watch For

Bare metal instances remain in preview; check regional availability with your account team. Z4D's 400 Gbps networking doubles Z3's bandwidth, enabling denser storage nodes.


Cloudflare BEACON: Billions of Real-User Performance Measurements Now Public

The Signal

Cloudflare published BEACON, a free dataset of billions of anonymized RUM measurements from 10,000+ sites in BigQuery.

What Changed

  • Dataset covers Core Web Vitals (LCP, CLS, INP) with full histograms, not just P75 aggregates.
  • Includes LCP and INP sub-parts: TTFB, load/render delays, input/processing/presentation timing breakdowns.
  • Built on RUM Archive standards, expands that project's footprint 100-fold with daily updates.
  • Data spans all major browser engines with device, network, and geography dimensions.
  • Access via Google BigQuery at https://rumarchive.com/ with example queries provided.

Operational Impact

Engineers can now benchmark against real-world performance data at unprecedented scale and diversity. The dataset enables analysis of how budget hardware, throttled connections, and regional infrastructure affect actual users — not lab conditions. Soft navigation data shows client-side routing renders 2-3x faster than hard navigations, but landing pages are significantly slower. Teams can join BEACON with external data sources for custom correlation analysis.

Watch For

Cloudflare plans to add more metrics and dimensions over time. The Cloudflare Radar Web Performance section will pair BEACON with Internet Quality Index data to separate site performance from network quality.


Quick Reads

  • MCP Python SDK — OAuth secrets leaked to malicious servers in versions before 1.30.0 and 2.2.0.
  • ShinyHunters — Breached FBI jobs site after member's arrest, exploiting unpatched PeopleSoft zero-day vulnerability.
  • Google Cloud Z4D — New AMD EPYC VMs offer 84TB local SSD with 15.6M IOPS performance.
  • Cloudflare BEACON — Billions of real-user performance measurements now available free in BigQuery dataset.

Subscribe to Signal Field

Data & infrastructure news. Subscribers get new posts by email a day before they go live on the site.

Email signup is coming soon — in the meantime, follow the Signal Field RSS feed.

Need a Custom MCP System?

Configuration & integration for your stack — from tool selection to production deployment. The directory recommends. The consultancy configures.

Get Started →