github.com/modelcontextprotocol/go-sdk
The official Go SDK for Model Context Protocol servers and clients. Maintained in collaboration with Google.
Activity
- Latest release
- 1w ago
- Total releases
- 33
- Cadence
- ~7 days
- Last 12 months
- 23
Reach
- Stars
- 5.1k
Details
- First release
- Jul 01, 2025
| Version | Released | |
|---|---|---|
v1.8.0
minor
|
v1.8.0
minor
Dependencies (8)
|
|
v1.8.0-pre.2
pre
|
v1.8.0-pre.2
pre
Dependencies (8)
|
|
v1.8.0-pre.1
pre
|
v1.8.0-pre.1
pre
Dependencies (8)
|
|
v1.7.0
minor
|
v1.7.0
minor
Dependencies (8)
|
|
v1.7.0-pre.3
pre
|
v1.7.0-pre.3
pre
Dependencies (8)
|
|
v1.7.0-pre.2
pre
|
v1.7.0-pre.2
pre
Dependencies (8)
|
|
v1.7.0-pre.1
pre
|
v1.7.0-pre.1
pre
Dependencies (8)
|
|
v1.6.1
patch
|
v1.6.1
patch
Dependencies (7)
|
|
v1.6.0
minor
|
v1.6.0
minor
Dependencies (7)
|
|
v1.6.0-pre.1
pre
|
v1.6.0-pre.1
pre
Dependencies (7)
|
|
v1.5.0-pre.1
pre
|
v1.5.0-pre.1
pre
Dependencies (7)
|
|
v1.5.0
minor
|
v1.5.0
minor
Dependencies (7)
|
|
v1.4.1
patch
|
v1.4.1
patch
Dependencies (7)
|
|
v1.4.0
minor
2 CVEs
CVE-2026-33252
GO-2026-4773
GHSA-89xv-2j6f-qhc8
Mar 23, 2026
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
GO-2026-4770
GHSA-q382-vc8q-7jhj
Mar 23, 2026
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev |
v1.4.0
minor
Dependencies (7)
|
|
v1.3.1
patch
3 CVEs
CVE-2026-34742
GO-2026-5771
GHSA-xw59-hvm2-8pj6
Jun 25, 2026
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.0
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33252
GO-2026-4773
GHSA-89xv-2j6f-qhc8
Mar 23, 2026
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
GO-2026-4770
GHSA-q382-vc8q-7jhj
Mar 23, 2026
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev |
v1.3.1
patch
Dependencies (7)
|
|
v1.3.0-pre.1
pre
4 CVEs
CVE-2026-34742
GO-2026-5771
GHSA-xw59-hvm2-8pj6
Jun 25, 2026
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.0
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33252
GO-2026-4773
GHSA-89xv-2j6f-qhc8
Mar 23, 2026
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
GO-2026-4770
GHSA-q382-vc8q-7jhj
Mar 23, 2026
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-27896
GO-2026-4569
GHSA-wvj2-96wp-fq3f
Mar 10, 2026
MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk Fixed in
1.3.1
References Updated Mar 23, 2026 · Source: OSV.dev |
v1.3.0-pre.1
pre
Dependencies (6)
|
|
v1.3.0
minor
4 CVEs
CVE-2026-34742
GO-2026-5771
GHSA-xw59-hvm2-8pj6
Jun 25, 2026
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.0
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33252
GO-2026-4773
GHSA-89xv-2j6f-qhc8
Mar 23, 2026
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
GO-2026-4770
GHSA-q382-vc8q-7jhj
Mar 23, 2026
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-27896
GO-2026-4569
GHSA-wvj2-96wp-fq3f
Mar 10, 2026
MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk Fixed in
1.3.1
References Updated Mar 23, 2026 · Source: OSV.dev |
v1.3.0
minor
Dependencies (6)
|
|
v1.2.0
minor
4 CVEs
CVE-2026-34742
GO-2026-5771
GHSA-xw59-hvm2-8pj6
Jun 25, 2026
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.0
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33252
GO-2026-4773
GHSA-89xv-2j6f-qhc8
Mar 23, 2026
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
GO-2026-4770
GHSA-q382-vc8q-7jhj
Mar 23, 2026
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-27896
GO-2026-4569
GHSA-wvj2-96wp-fq3f
Mar 10, 2026
MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk Fixed in
1.3.1
References Updated Mar 23, 2026 · Source: OSV.dev |
v1.2.0
minor
Dependencies (6)
|
|
v1.2.0-pre.2
pre
4 CVEs
CVE-2026-34742
GO-2026-5771
GHSA-xw59-hvm2-8pj6
Jun 25, 2026
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.0
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33252
GO-2026-4773
GHSA-89xv-2j6f-qhc8
Mar 23, 2026
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
GO-2026-4770
GHSA-q382-vc8q-7jhj
Mar 23, 2026
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-27896
GO-2026-4569
GHSA-wvj2-96wp-fq3f
Mar 10, 2026
MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk Fixed in
1.3.1
References Updated Mar 23, 2026 · Source: OSV.dev |
v1.2.0-pre.2
pre
Dependencies (6)
|
|
v1.2.0-pre.1
pre
4 CVEs
CVE-2026-34742
GO-2026-5771
GHSA-xw59-hvm2-8pj6
Jun 25, 2026
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.0
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33252
GO-2026-4773
GHSA-89xv-2j6f-qhc8
Mar 23, 2026
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
GO-2026-4770
GHSA-q382-vc8q-7jhj
Mar 23, 2026
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-27896
GO-2026-4569
GHSA-wvj2-96wp-fq3f
Mar 10, 2026
MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk Fixed in
1.3.1
References Updated Mar 23, 2026 · Source: OSV.dev |
v1.2.0-pre.1
pre
Dependencies (6)
|
|
v1.1.0-pre.2
pre
4 CVEs
CVE-2026-34742
GO-2026-5771
GHSA-xw59-hvm2-8pj6
Jun 25, 2026
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.0
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33252
GO-2026-4773
GHSA-89xv-2j6f-qhc8
Mar 23, 2026
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
GO-2026-4770
GHSA-q382-vc8q-7jhj
Mar 23, 2026
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-27896
GO-2026-4569
GHSA-wvj2-96wp-fq3f
Mar 10, 2026
MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk Fixed in
1.3.1
References Updated Mar 23, 2026 · Source: OSV.dev |
v1.1.0-pre.2
pre
Dependencies (6)
|
|
v1.1.0
minor
4 CVEs
CVE-2026-34742
GO-2026-5771
GHSA-xw59-hvm2-8pj6
Jun 25, 2026
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.0
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33252
GO-2026-4773
GHSA-89xv-2j6f-qhc8
Mar 23, 2026
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
GO-2026-4770
GHSA-q382-vc8q-7jhj
Mar 23, 2026
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-27896
GO-2026-4569
GHSA-wvj2-96wp-fq3f
Mar 10, 2026
MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk Fixed in
1.3.1
References Updated Mar 23, 2026 · Source: OSV.dev |
v1.1.0
minor
Dependencies (6)
|
|
v1.1.0-pre.1
pre
4 CVEs
CVE-2026-34742
GO-2026-5771
GHSA-xw59-hvm2-8pj6
Jun 25, 2026
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.0
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33252
GO-2026-4773
GHSA-89xv-2j6f-qhc8
Mar 23, 2026
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
GO-2026-4770
GHSA-q382-vc8q-7jhj
Mar 23, 2026
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-27896
GO-2026-4569
GHSA-wvj2-96wp-fq3f
Mar 10, 2026
MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk Fixed in
1.3.1
References Updated Mar 23, 2026 · Source: OSV.dev |
v1.1.0-pre.1
pre
Dependencies (6)
|
|
v1.0.0
major
4 CVEs
CVE-2026-34742
GO-2026-5771
GHSA-xw59-hvm2-8pj6
Jun 25, 2026
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.0
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33252
GO-2026-4773
GHSA-89xv-2j6f-qhc8
Mar 23, 2026
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
GO-2026-4770
GHSA-q382-vc8q-7jhj
Mar 23, 2026
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-27896
GO-2026-4569
GHSA-wvj2-96wp-fq3f
Mar 10, 2026
MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk Fixed in
1.3.1
References Updated Mar 23, 2026 · Source: OSV.dev |
v1.0.0
major
Dependencies (5)
|
|
v0.8.0
minor
4 CVEs
CVE-2026-34742
GO-2026-5771
GHSA-xw59-hvm2-8pj6
Jun 25, 2026
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.0
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33252
GO-2026-4773
GHSA-89xv-2j6f-qhc8
Mar 23, 2026
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
GO-2026-4770
GHSA-q382-vc8q-7jhj
Mar 23, 2026
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-27896
GO-2026-4569
GHSA-wvj2-96wp-fq3f
Mar 10, 2026
MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk Fixed in
1.3.1
References Updated Mar 23, 2026 · Source: OSV.dev |
v0.8.0
minor
Dependencies (5)
|
|
v0.7.0
minor
4 CVEs
CVE-2026-34742
GO-2026-5771
GHSA-xw59-hvm2-8pj6
Jun 25, 2026
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.0
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33252
GO-2026-4773
GHSA-89xv-2j6f-qhc8
Mar 23, 2026
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
GO-2026-4770
GHSA-q382-vc8q-7jhj
Mar 23, 2026
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-27896
GO-2026-4569
GHSA-wvj2-96wp-fq3f
Mar 10, 2026
MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk Fixed in
1.3.1
References Updated Mar 23, 2026 · Source: OSV.dev |
v0.7.0
minor
Dependencies (5)
|
|
v0.6.0
minor
4 CVEs
CVE-2026-34742
GO-2026-5771
GHSA-xw59-hvm2-8pj6
Jun 25, 2026
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.0
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33252
GO-2026-4773
GHSA-89xv-2j6f-qhc8
Mar 23, 2026
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
GO-2026-4770
GHSA-q382-vc8q-7jhj
Mar 23, 2026
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-27896
GO-2026-4569
GHSA-wvj2-96wp-fq3f
Mar 10, 2026
MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk Fixed in
1.3.1
References Updated Mar 23, 2026 · Source: OSV.dev |
v0.6.0
minor
Dependencies (5)
|
|
v0.5.0
minor
4 CVEs
CVE-2026-34742
GO-2026-5771
GHSA-xw59-hvm2-8pj6
Jun 25, 2026
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.0
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33252
GO-2026-4773
GHSA-89xv-2j6f-qhc8
Mar 23, 2026
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
GO-2026-4770
GHSA-q382-vc8q-7jhj
Mar 23, 2026
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-27896
GO-2026-4569
GHSA-wvj2-96wp-fq3f
Mar 10, 2026
MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk Fixed in
1.3.1
References Updated Mar 23, 2026 · Source: OSV.dev |
v0.5.0
minor
Dependencies (4)
|
|
v0.4.0
minor
4 CVEs
CVE-2026-34742
GO-2026-5771
GHSA-xw59-hvm2-8pj6
Jun 25, 2026
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.0
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33252
GO-2026-4773
GHSA-89xv-2j6f-qhc8
Mar 23, 2026
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
GO-2026-4770
GHSA-q382-vc8q-7jhj
Mar 23, 2026
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-27896
GO-2026-4569
GHSA-wvj2-96wp-fq3f
Mar 10, 2026
MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk Fixed in
1.3.1
References Updated Mar 23, 2026 · Source: OSV.dev |
v0.4.0
minor
Dependencies (4)
|
|
v0.3.1
patch
4 CVEs
CVE-2026-34742
GO-2026-5771
GHSA-xw59-hvm2-8pj6
Jun 25, 2026
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.0
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33252
GO-2026-4773
GHSA-89xv-2j6f-qhc8
Mar 23, 2026
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
GO-2026-4770
GHSA-q382-vc8q-7jhj
Mar 23, 2026
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-27896
GO-2026-4569
GHSA-wvj2-96wp-fq3f
Mar 10, 2026
MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk Fixed in
1.3.1
References Updated Mar 23, 2026 · Source: OSV.dev |
v0.3.1
patch
Dependencies (4)
|
|
v0.3.0
minor
4 CVEs
CVE-2026-34742
GO-2026-5771
GHSA-xw59-hvm2-8pj6
Jun 25, 2026
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.0
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33252
GO-2026-4773
GHSA-89xv-2j6f-qhc8
Mar 23, 2026
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
GO-2026-4770
GHSA-q382-vc8q-7jhj
Mar 23, 2026
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-27896
GO-2026-4569
GHSA-wvj2-96wp-fq3f
Mar 10, 2026
MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk Fixed in
1.3.1
References Updated Mar 23, 2026 · Source: OSV.dev |
v0.3.0
minor
Dependencies (4)
|
|
v0.2.0
minor
4 CVEs
CVE-2026-34742
GO-2026-5771
GHSA-xw59-hvm2-8pj6
Jun 25, 2026
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.0
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33252
GO-2026-4773
GHSA-89xv-2j6f-qhc8
Mar 23, 2026
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
GO-2026-4770
GHSA-q382-vc8q-7jhj
Mar 23, 2026
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-27896
GO-2026-4569
GHSA-wvj2-96wp-fq3f
Mar 10, 2026
MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk Fixed in
1.3.1
References Updated Mar 23, 2026 · Source: OSV.dev |
v0.2.0
minor
Dependencies (3)
|
|
v0.1.0
initial
4 CVEs
CVE-2026-34742
GO-2026-5771
GHSA-xw59-hvm2-8pj6
Jun 25, 2026
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.0
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33252
GO-2026-4773
GHSA-89xv-2j6f-qhc8
Mar 23, 2026
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
GO-2026-4770
GHSA-q382-vc8q-7jhj
Mar 23, 2026
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk Fixed in
1.4.1
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-27896
GO-2026-4569
GHSA-wvj2-96wp-fq3f
Mar 10, 2026
MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdk Fixed in
1.3.1
References Updated Mar 23, 2026 · Source: OSV.dev |
v0.1.0
initial
Dependencies (2)
|