Skip to content

[container-image-scan] Container findings for ghcr.io/github/github-mcp-server:v1.8.0 #51328

Description

@github-actions

Summary

Image: ghcr.io/github/github-mcp-server:v1.8.0
Pinned reference: ghcr.io/github/github-mcp-server:v1.8.0@sha256:d5a18c04b92714c309eb46a2305087e91a4dbd80420f6e462656699f95093520

  • Vulnerabilities: 1 Critical, 3 High, 2 Medium, 8 Negligible
  • License policy violations: 6

Vulnerabilities

1 Critical, 3 High (expand for full list)
  • [Critical] CVE-2026-5450 — libc6@2.36-9+deb12u14 — no fix available yet. (securitytracker.debian.org/redacted)
  • [High] CVE-2026-5928 — libc6@2.36-9+deb12u14 — no fix available yet. (securitytracker.debian.org/redacted)
  • [High] CVE-2026-5435 — libc6@2.36-9+deb12u14 — no fix available yet. (securitytracker.debian.org/redacted)
  • [High] GO-2026-5970 — golang.org/x/text@v0.37.0 — fix: 0.39.0. https://go.dev/issue/80142
2 Medium, 8 Negligible (expand for full list)

Licenses

6 rejected/unknown license findings
  • base-files@12.4+deb12u15 — GPL-2.0-or-later
  • libssl3@3.0.20-1~deb12u2 — Artistic, GPL-1.0-only, GPL-1.0-or-later
  • tzdata@2026b-0+deb12u1 — public-domain
  • libc6@2.36-9+deb12u14 — GPL-2.0-only, HPND, LGPL-2.1-or-later, Spencer-94
  • media-types@10.0.0 — ad-hoc
  • netbase@6.4 — GPL-2.0-only

Remediation

  • Rebuild the github-mcp-server image on top of a patched Debian base (libc6 >= a version fixing CVE-2026-5450/5928/5435) once upstream releases updated packages; track glibc security advisories.
  • Bump the Go module golang.org/x/text to v0.39.0 or later to resolve GO-2026-5970.
  • Review GPL/Artistic-licensed base packages (base-files, libssl3, libc6, netbase) against organizational license policy; these are typically unavoidable in Debian-based images but should be explicitly allow-listed if acceptable.

Generated by 🛡️ Daily Container Image Security Scan · auto · 434.8 AIC · ⌖ 3.45 AIC · ⊞ 6.5K · ◷

Activity

  1. github-actions commented on Aug 8, 2026

    @github-actions
    ContributorAuthor

    🍪 Issue Monster selected this for Copilot\n\nI've identified this issue as a good candidate for automated resolution and requested assignment to the Copilot coding agent.\n\nIf assignment succeeds, the Copilot coding agent will analyze the issue and create a pull request with the fix.\n\nOm nom nom! 🍪

    🍪 Om nom nom by Issue Monster · gpt54 · 2.77 AIC · ⌖ 5.03 AIC · ⊞ 10.1K · ◷

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions