{"data":{"id":"31a33138-1d47-4a88-afe5-32b25e954629","title":"GHSA-wvj2-96wp-fq3f: MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity","summary":"The Go MCP SDK parsed JSON-RPC and MCP messages with Go's standard encoding/json.Unmarshal, which matches keys case-insensitively and folds Unicode characters such as ſ (U+017F) and K (U+212A) to ASCII. A malicious MCP peer could send non-standard field casing, such as \"Method\" instead of \"method\", that the SDK silently accepted. This could let such messages bypass intermediary proxies or policy layers that match exact field names, and it made the Go SDK inconsistent with the case-sensitive TypeScript and Python SDKs.","solution":"Fixed in v1.3.1. The SDK replaced Go's standard JSON unmarshaling with a case-sensitive decoder (github.com/segmentio/encoding) in commit 7b8d81c. Users are advised to update to v1.3.1.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-wvj2-96wp-fq3f","publishedAt":"2026-02-26T22:20:08.000Z","cveId":"CVE-2026-27896","cweIds":["CWE-178","CWE-436"],"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["github.com/modelcontextprotocol/go-sdk@< 1.3.1 (fixed: 1.3.1)"],"affectedPackageNames":["github.com/modelcontextprotocol/go-sdk"],"affectedPackageRefs":["go:github.com/modelcontextprotocol/go-sdk"],"affectedVendors":[],"affectedVendorsRaw":["MCP Go SDK","Model Context Protocol"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00457,"epssCheckedAt":"2026-10-10T04:57:22.500Z","kevDateAdded":null,"advisoryAliases":["GHSA-wvj2-96wp-fq3f"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-02-26T22:20:08.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}