
🟠 CVE-2026-34742 - High The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.0, the Model Context Protocol (MCP) Go SDK does not enable DNS rebinding protection by default for HTTP-based servers. Wh... https://www.thehackerwire.com/vulnerability/CVE-2026-34742/ https://t.co/wZ6jcPbTqJ
Post summary
The tweet announces CVE‑2026‑34742 as a high‑severity DNS rebinding vulnerability in the Go MCP SDK before version 1.4.0, noting that default protection is disabled for HTTP servers. It contains no PoC, exploit, or patch information.

