FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Response leak in SSE handlers · Issue #1450 · modelcontextprotocol/python-sdk · GitHub

Repository navigation

Response leak in SSE handlers #1450

Description

I found a resource leak in the streamable HTTP client. When SSE streaming fails with an exception, the HTTP response isn't closed.

Location:
src/mcp/client/streamable_http.py:

  • _handle_sse_response (line 336)
  • _handle_resumption_request (line 251)

The Issue:
python
async def _handle_sse_response(self, response: httpx.Response, ...):
try:
event_source = EventSource(response)
async for sse in event_source.aiter_sse():
if is_complete:
await response.aclose() # Only closed here
break
except Exception as e:
await ctx.read_stream_writer.send(e)
# response leaked!

If the SSE iteration raises an exception (malformed JSON, network error, etc.), the response is never closed.

Impact:
Connection pool gets exhausted in long-running clients, eventually causing new requests to hang or fail.

Fix:
try:
...
except Exception as e:
...
finally:
await response.aclose()

Both methods need this fix.

Env:
Python SDK version: 1.1.2 (or main branch)
Python: 3.12
Transport: StreamableHTTP

Activity

  1. maxisbey commented on Oct 9, 2025

    Contributor

    Thanks for the report! Please provide a minimal reproducible example code snippet we can run to confirm the issue

  2. added
    bugSomething isn't working
    needs reproneeds additional information to be able to reproduce bug
    on Oct 9, 2025
  3. certainly-param commented on Oct 17, 2025

    Author

    Hey!
    I've created a PR with the reproduction tests you requested.
    The tests confirm the resource leak - when SSE streaming fails with exceptions, the HTTP response doesn't get closed properly in both _handle_sse_response and _handle_resumption_request.

    I added two test files:

    1. A standalone reproduction script (resource_leak_reproduction.py) that shows the issue clearly.
    2. Proper pytest tests (tests/client/test_streamable_http_resource_leak.py) that verify the leak and demonstrate how the fix should work

    You can run the tests to see the problem in action. The fix is straightforward - just need finally blocks to ensure response.aclose() always gets called.

    PR: #1490

  4. added a commit that references this issue on Oct 17, 2025
    d2f7de8
  5. added
    P0Broken core functionality, security issues, critical missing feature
    ready for workEnough information for someone to start working on
    and removed
    bugSomething isn't working
    on Oct 17, 2025
  6. felixweinberger commented on Oct 17, 2025

    Contributor

    Hi @certainly-param thank you for the detailed test case demonstration!

  7. added
    P2Moderate issues affecting some users, edge cases, potentially valuable feature
    and removed
    P0Broken core functionality, security issues, critical missing feature
    on Feb 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P2Moderate issues affecting some users, edge cases, potentially valuable featurebugSomething isn't workingneeds reproneeds additional information to be able to reproduce bugready for workEnough information for someone to start working on

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions


      Back | FazBrowse Home | New Git URL