VDB

GO-2026-4773

GO-2026-4773 PUBLISHED

Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk

Affected Products

VendorProductVersions
chainguardflux-operator0
chainguardgitlab-workhorse-ce-18.80
chainguardglab0
wolfiferretdb0, 0, 0
chainguardgitlab-workhorse-ce-18.90
wolfiglab0, 0, 0
chainguardflux-operator-fips0
wolfiopencost0, 0, 0
wolfijaeger-20, 0, 0
chainguarddatadog-agent-7.760
chainguardopencost-fips0, 0
wolfiosv-scanner0, 0, 0
github.commodelcontextprotocol/go-sdk0, 0
chainguardgitlab-workhorse-ce-fips-18.80
chainguardlivekit-cli0, 0
chainguardferretdb0
chainguardopencost0, 0
wolfidatadog-agent-7.760, 0, 0
chainguardosv-scanner0, 0
chainguardjaeger-2-fips0, 0

…and 3 more

Timeline

  • Mar 23, 2026 CVE Published
  • Mar 25, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›