VendorsLF Projectsmcp_go_sdkany version
Vulnerabilities

LF Projects MCP Go SDK any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2026-34742
Model Context Protocol Go SDK: DNS Rebinding Protection Disabled by Default for Servers Running on Localhost
Published 2026-04-02 · Modified
8.1EPSS 0.005
CVE-2026-27896
MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity
Published 2026-02-26 · Modified
7.5EPSS 0.003
CVE-2026-33252
MCP Go SDK Allows Cross-Site Tool Execution for HTTP Servers without Authorizatrion
Published 2026-03-23 · Analyzed
7.1EPSS 0.002