{"id":"CVE-2026-27896","title":"MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity","summary":"The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing in versions prior to 1.3.1. Go's standard library performs case-insensitive matching of JSON keys to struct field tags — a field tagg…","severity":"high","cvss":7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N","cvssSource":"cna","cwe":["CWE-178","CWE-436"],"vendor":"modelcontextprotocol","product":"go-sdk","affected":["go-sdk < 1.3.1"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-02-26T17:06:14.973622Z"},"published":"2026-02-26","updated":"2026-09-16","sourceUpdated":"2026-09-16T12:04:21.685Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-27896","references":[{"url":"https://github.com/modelcontextprotocol/go-sdk/security/advisories/GHSA-wvj2-96wp-fq3f","label":"https://github.com/modelcontextprotocol/go-sdk/security/advisories/GHSA-wvj2-96wp-fq3f"},{"url":"https://github.com/modelcontextprotocol/go-sdk/commit/7b8d81c264074404abdf5aa16e2cf0c2d9c64cc0","label":"https://github.com/modelcontextprotocol/go-sdk/commit/7b8d81c264074404abdf5aa16e2cf0c2d9c64cc0"}],"tags":["cve.org"],"epss":0.00255,"epssPercentile":0.17312,"ingestedAt":"2026-09-16T12:55:21.866Z","slug":"CVE-2026-27896","body":"## Overview\n\nThe Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing in versions prior to 1.3.1. Go's standard library performs case-insensitive matching of JSON keys to struct field tags — a field tagged json:\"method\" would also match \"Method\", \"METHOD\", etc. This violated the JSON-RPC 2.0 specification, which defines exact field names. A malicious MCP peer may have been able to send protocol messages with non-standard field casing that the SDK would silently accept. This had the potential for bypassing intermediary inspection and coss-implementation inconsistency. Go's standard JSON unmarshaling was replaced with a case-sensitive decoder in commit 7b8d81c. Users are advised to update to v1.3.1 to resolve this issue.\n\n## Affected\n\n- `go-sdk < 1.3.1`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}