VDB
GO-2026-4773
GO-2026-4773
PUBLISHED
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| chainguard | flux-operator | 0 |
| chainguard | gitlab-workhorse-ce-18.8 | 0 |
| chainguard | glab | 0 |
| wolfi | ferretdb | 0, 0, 0 |
| chainguard | gitlab-workhorse-ce-18.9 | 0 |
| wolfi | glab | 0, 0, 0 |
| chainguard | flux-operator-fips | 0 |
| wolfi | opencost | 0, 0, 0 |
| wolfi | jaeger-2 | 0, 0, 0 |
| chainguard | datadog-agent-7.76 | 0 |
| chainguard | opencost-fips | 0, 0 |
| wolfi | osv-scanner | 0, 0, 0 |
| github.com | modelcontextprotocol/go-sdk | 0, 0 |
| chainguard | gitlab-workhorse-ce-fips-18.8 | 0 |
| chainguard | livekit-cli | 0, 0 |
| chainguard | ferretdb | 0 |
| chainguard | opencost | 0, 0 |
| wolfi | datadog-agent-7.76 | 0, 0, 0 |
| chainguard | osv-scanner | 0, 0 |
| chainguard | jaeger-2-fips | 0, 0 |
…and 3 more
Timeline
- Mar 23, 2026 CVE Published
- Mar 25, 2026 CVE Updated