FastMCP OAuth token audience flaw (CVE-2025-69196) fixed in 2.14.2
FastMCP versions prior to 2.14.2 did not respect the resource parameter submitted by clients in authorization and token requests, issuing tokens for the base_url given to the OAuthProxy rather than explicitly for the MCP server. The issue was patched in version 2.14.2.
Disclosed 16 March 2026 · Record updated 13 September 2026
Impact
OAuth tokens were issued with an incorrect audience (the configured base_url instead of the specific MCP server), weakening token binding for MCP applications built on FastMCP.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2025-69196
