Skip to main content
// menu
×
>
Loading…
// threat_lookup
×
☰
INTELLIGENCE ROOM
// cybersoc_platform
Dashboard
CVE/RCE
APT
News
Reports
Pulse
SOON
Graph
SOON
Market
SOON
Playback
SOON
NOMINAL
0
Sign in
Join →
CVE-2026-33252 — The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.1, the Go SDK's Streamable HTTP transport accepted browser-generated cross-site `POST` requests without validating the `Or — CVE Database · The Intelligence Room