| id: GO-2026-4569 |
| modules: |
| - module: github.com/modelcontextprotocol/go-sdk |
| versions: |
| - fixed: 1.3.1 |
| vulnerable_at: 1.3.0 |
| summary: MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk |
| cves: |
| - CVE-2026-27896 |
| ghsas: |
| - GHSA-wvj2-96wp-fq3f |
| references: |
| - advisory: https://github.com/modelcontextprotocol/go-sdk/security/advisories/GHSA-wvj2-96wp-fq3f |
| - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-27896 |
| - fix: https://github.com/modelcontextprotocol/go-sdk/commit/7b8d81c264074404abdf5aa16e2cf0c2d9c64cc0 |
| source: |
| id: GHSA-wvj2-96wp-fq3f |
| created: 2026-03-06T14:56:49.059263-05:00 |
| review_status: UNREVIEWED |