GHSA-wvj2-96wp-fq3f: MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity
- Identifiers
- CVE-2026-27896GHSA-wvj2-96wp-fq3f
- Published
- Record updated
- Affected
- github.com/modelcontextprotocol/go-sdk < 1.3.1
- Fixed in
- 1.3.1
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.5%
Summary
The Go MCP SDK parsed JSON-RPC and MCP messages with Go's standard encoding/json.Unmarshal, which matches keys case-insensitively and folds Unicode characters such as ſ (U+017F) and K (U+212A) to ASCII. A malicious MCP peer could send non-standard field casing, such as "Method" instead of "method", that the SDK silently accepted. This could let such messages bypass intermediary proxies or policy layers that match exact field names, and it made the Go SDK inconsistent with the case-sensitive TypeScript and Python SDKs.
Mitigation
Fixed in v1.3.1. The SDK replaced Go's standard JSON unmarshaling with a case-sensitive decoder (github.com/segmentio/encoding) in commit 7b8d81c. Users are advised to update to v1.3.1.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- github.com/modelcontextprotocol/go-sdkGoLLM dependency since 2025-07-01 · 1 tracked dependent
Topics
Related items
- LowAnthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection FlawsSimilar attack · The Hacker News
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading