Skip to main content

Vendor/product archive

lfprojects / mcp_go_sdk CVEs

Beta · best-effort

3 CVEs tagged to lfprojects / mcp_go_sdk0 Critical, 3 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-34742

Published Apr 2, 2026

The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.0, the Model Context Protocol (MCP) Go SDK does not enable DNS rebinding protection by default for HTTP-based…

CVSS 7.6 · High
evidence mentions
8
Buzz score
35.0
Vendor/product tagsBeta · best-effort

CVE-2026-33252

Published Mar 24, 2026

The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.1, the Go SDK's Streamable HTTP transport accepted browser-generated cross-site `POST` requests without valid…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-27896

Published Feb 26, 2026

The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing in versions prior to 1.3.1. Go's standard library performs case-insensitive…

CVSS 7.0 · High
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1