Skip to content

[Schema] SEP-2106: Harden SchemaValidator against external $ref SSRF and composition DoS #358

Description

@chr-hertel

Implements the security hardening portion of SEP-2106 for the MCP Spec 2026-07-28 release.

Tracked by umbrella #337.

Spec rationale

Once $ref and rich composition land in inputSchema/outputSchema, naive validators are exposed to: SSRF via external $ref URIs, and DoS via pathological compositions / deep nesting / large subschema counts.

PHP SDK changes

  • SchemaValidator MUST NOT auto-dereference external $ref URIs (block any non-same-document reference by default).
  • Bound: schema depth, subschema count, validation time.
  • Configurable limits with sensible defaults (mirror existing session-store DoS limit ergonomics).
  • Add regression tests with adversarial schemas.

Related

Activity

  1. added
    SchemaIssues & PRs related to the Schema component
    P0Broken core functionality, security issues, critical missing feature
    improves spec complianceImproves consistency with other SDKs such as TyepScript
    enhancementRequest for a new feature that's not currently supported
    on May 26, 2026
  2. added
    2026-07-28All issues and PRs related to the spec release 2026-07-28
    on May 26, 2026
  3. removed
    P0Broken core functionality, security issues, critical missing feature
    on Aug 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    2026-07-28All issues and PRs related to the spec release 2026-07-28SchemaIssues & PRs related to the Schema componentenhancementRequest for a new feature that's not currently supportedimproves spec complianceImproves consistency with other SDKs such as TyepScript

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions