Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wvj2-96wp-fq3f | MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity |
Tue, 14 Apr 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lfprojects
Lfprojects mcp Go Sdk |
|
| CPEs | cpe:2.3:a:lfprojects:mcp_go_sdk:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lfprojects
Lfprojects mcp Go Sdk |
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Sat, 28 Feb 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 27 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Feb 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Modelcontextprotocol
Modelcontextprotocol go-sdk |
|
| Vendors & Products |
Modelcontextprotocol
Modelcontextprotocol go-sdk |
Thu, 26 Feb 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing in versions prior to 1.3.1. Go's standard library performs case-insensitive matching of JSON keys to struct field tags — a field tagged json:"method" would also match "Method", "METHOD", etc. This violated the JSON-RPC 2.0 specification, which defines exact field names. A malicious MCP peer may have been able to send protocol messages with non-standard field casing that the SDK would silently accept. This had the potential for bypassing intermediary inspection and coss-implementation inconsistency. Go's standard JSON unmarshaling was replaced with a case-sensitive decoder in commit 7b8d81c. Users are advised to update to v1.3.1 to resolve this issue. | |
| Title | MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity | |
| Weaknesses | CWE-178 CWE-436 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-26T17:06:41.150Z
Reserved: 2026-02-24T15:19:29.717Z
Link: CVE-2026-27896
Updated: 2026-02-26T17:06:34.996Z
Status : Analyzed
Published: 2026-02-26T01:16:25.630
Modified: 2026-04-14T00:40:00.510
Link: CVE-2026-27896
OpenCVE Enrichment
Updated: 2026-04-17T14:45:21Z
Github GHSA