CVE-2026-27896 - MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity

CVE-2026-27896 - MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity

CVE ID : CVE-2026-27896 Published : Feb. 26, 2026, 12:47 a.m. | 16 minutes ago Description : The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing in versions prior to 1.3.1. Go's standard library performs case-insensitive matching of JSON keys to struct field tags — a field tagged json:

CVE Details

Published
Feb. 26, 2026