CVE-2026-27896
modelcontextprotocol go-sdk, Migration Toolkit for Virtualization, OpenShift Lightspeed
The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing in versions prior to 1.3.1. Go's standard library performs case-insensitive matching of JSON keys to struct field tags — a field tagged json:"method" would also match "Method", "METHOD", etc. This violated the JSON-RPC 2.0 specification, which defines exact field names. A malicious MCP peer may have been able to send protocol messages with non-standard field casing that the SDK would silently accept. This had the potential for bypassing intermediary inspection and coss-implementation inco...
- CVSS
- 7
- EPSS
- 0.26% 17.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.02.26