CVE-2026-81092 | mark3labs mcp-go up to 0.55.x HTTP Transport streamable_http.go StreamableHTTPServer.ServeHTTP Host information disclosure
A vulnerability was found in mark3labs mcp-go up to 0.55.x and classified as problematic. This affects the function StreamableHTTPServer.ServeHTTP of the file server/streamable_http.go of the component HTTP Transport. The manipulation of the argument Host results in information disclosure.
This vulnerability was named CVE-2026-81092. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More