github.com/modelcontextprotocol/go-sdk
Go3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/modelcontextprotocol/go-sdkpage 1 of 1
- CVE-2026-27896HIGHCVSS 7.5EG 7.5✓ Fixed in 1.3.12026-02-26
The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing in versions prior to 1.3.1. Go's standard library performs case-insensitive matching of JSON keys to struct field tags — a field tagg…
- CVE-2026-33252HIGHCVSS 7.1EG 7.1✓ Fixed in 1.4.12026-03-24
The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.1, the Go SDK's Streamable HTTP transport accepted browser-generated cross-site `POST` requests without validating the `Origin` header and without requiring `Content-Typ…
- CVE-2026-34742HIGHCVSS 8.1EG 8.1✓ Fixed in 1.4.02026-04-02
The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.0, the Model Context Protocol (MCP) Go SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on localhost …
Check whether github.com/modelcontextprotocol/go-sdk is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/modelcontextprotocol/go-sdk CVEs against the assets you own.
Start Free Scan →