CVE-2026-27896 describes a vulnerability in the Go MCP SDK (versions prior to 1.3.1) where its JSON parser allowed case-insensitive matching of JSON keys, violating the JSON-RPC 2.0 specification. This flaw could enable a malicious MCP peer to send non-standard protocol messages that bypass intermediary inspection and cause cross-implementation inconsistencies. With a CVSS score of 7.0 (HIGH), this vulnerability has a network attack vector and low attack complexity, potentially leading to high impact on confidentiality and integrity, though not availability. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available, although it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.1CPE matchmatch criteria | cpe:2.3:a:lfprojects:mcp_go_sdk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.