A vulnerability categorized as critical has been discovered in modelcontextprotocol go-sdk up to 1.3.0. The affected element is an unknown function of the component MCP Protocol. Such manipulation leads to improper handling of case sensitivity.
This vulnerability is documented as CVE-2026-27896. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.