Skip to content

[container-image-scan] MCP Gateway CVE burn-down #65793

Description

@github-actions

MCP Gateway scan summary

Status: Upstream (owned by github/gh-aw-mcpg). Unique finding rows: 4 Critical, 57 High, 33 Medium, 15 Low, 37 Unknown; 0 license violations.

Images

Image Pinned reference Status
gh-aw-mcpg ghcr.io/github/gh-aw-mcpg:v0.4.30@sha256:ab5a436a1490438db473e4e3d4c973cb1d75e3cb233fb08b73d31b42d7d18fba upstream

Findings by severity

Critical
CVE-2026-63073: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-63073: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-75803: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-75803: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
High
CVE-2026-103111: pcre2@10.47-r1 (fix: 10.49-r0)
CVE-2026-14456: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-14456: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-14457: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-14457: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-17106: docker-cli@29.5.3-r0
CVE-2026-18798: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-18798: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-54873: libcrypto3@3.5.7-r0
CVE-2026-54873: libssl3@3.5.7-r0
CVE-2026-54874: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-54874: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-63072: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-63072: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-63075: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-63075: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-63076: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-63076: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-72897: libcrypto3@3.5.7-r0
CVE-2026-72897: libssl3@3.5.7-r0
CVE-2026-76642: libblkid@2.42.1-r0 (fix: 2.42.3-r0)
CVE-2026-76642: libmount@2.42.1-r0 (fix: 2.42.3-r0)
CVE-2026-78408: libblkid@2.42.1-r0 (fix: 2.42.3-r1)
CVE-2026-78408: libmount@2.42.1-r0 (fix: 2.42.3-r1)
CVE-2026-78409: libblkid@2.42.1-r0 (fix: 2.42.3-r0)
CVE-2026-78409: libmount@2.42.1-r0 (fix: 2.42.3-r0)
CVE-2026-78410: libblkid@2.42.1-r0 (fix: 2.42.3-r0)
CVE-2026-78410: libmount@2.42.1-r0 (fix: 2.42.3-r0)
CVE-2026-84042: crun@1.28-r0 (fix: 1.30.1-r0)
CVE-2026-84782: libcrypto3@3.5.7-r0
CVE-2026-84782: libssl3@3.5.7-r0
CVE-2026-84784: libcrypto3@3.5.7-r0
CVE-2026-84784: libssl3@3.5.7-r0
CVE-2026-85091: zlib@1.3.2-r0 (fix: 1.3.2-r1)
CVE-2026-86145: pcre2@10.47-r1 (fix: 10.48-r0)
CVE-2026-89157: pcre2@10.47-r1 (fix: 10.48-r0)
CVE-2026-89161: pcre2@10.47-r1 (fix: 10.48-r0)
CVE-2026-92543: docker-cli@29.5.3-r0 (fix: 29.8.2-r0)
GHSA-2v4p-qf9q-27wj: google.golang.org/grpc@v1.81.1 (fix: 1.82.2)
GHSA-f5mr-q85p-6hh6: github.com/sigstore/fulcio@v1.8.5 (fix: 1.8.6)
GHSA-hfg8-hc9c-6c3h: github.com/moby/go-archive@v0.2.0 (fix: 0.3.0)
GHSA-hrxh-6v49-42gf: google.golang.org/grpc@v1.81.1 (fix: 1.82.1)
GHSA-vp52-pcj8-j9qc: google.golang.org/grpc@v1.81.1 (fix: 1.83.1)
GO-2026-4970: stdlib@go1.26.4 (fix: 1.25.12, 1.26.5, 1.27.0-rc.2)
GO-2026-5026: stdlib@go1.26.3 (fix: 1.25.13, 1.26.6, 1.27.0-rc.3)
GO-2026-5026: stdlib@go1.26.4 (fix: 1.25.13, 1.26.6, 1.27.0-rc.3)
GO-2026-5037: stdlib@go1.26.3 (fix: 1.25.11, 1.26.4)
GO-2026-5942: stdlib@go1.26.3 (fix: 1.26.6, 1.27.0-rc.3)
GO-2026-5942: stdlib@go1.26.4 (fix: 1.26.6, 1.27.0-rc.3)
GO-2026-5970: golang.org/x/text@v0.38.0 (fix: 0.39.0)
GO-2026-5972: stdlib@go1.26.3 (fix: 1.25.13, 1.26.6, 1.27.0-rc.3)
GO-2026-5972: stdlib@go1.26.4 (fix: 1.25.13, 1.26.6, 1.27.0-rc.3)
GO-2026-6089: stdlib@go1.26.4 (fix: 1.25.13, 1.26.6, 1.27.0-rc.3)
GO-2026-6090: stdlib@go1.26.3 (fix: 1.25.13, 1.26.6, 1.27.0-rc.3)
GO-2026-6090: stdlib@go1.26.4 (fix: 1.25.13, 1.26.6, 1.27.0-rc.3)
GO-2026-6354: golang.org/x/crypto@v0.53.0 (fix: 0.56.0)
GO-2026-6355: golang.org/x/crypto@v0.53.0 (fix: 0.56.0)
Medium
CVE-2025-60876: busybox-binsh@1.37.0-r31
CVE-2025-60876: busybox@1.37.0-r31
CVE-2025-60876: ssl_client@1.37.0-r31
CVE-2026-27456: libblkid@2.42.1-r0 (fix: 2.41.4-r0, 2.42.3-r0)
CVE-2026-27456: libmount@2.42.1-r0 (fix: 2.41.4-r0, 2.42.3-r0)
CVE-2026-35189: libcrypto3@3.5.7-r0
CVE-2026-35189: libssl3@3.5.7-r0
CVE-2026-42772: libcrypto3@3.5.7-r0
CVE-2026-42772: libssl3@3.5.7-r0
CVE-2026-53493: docker-cli@29.5.3-r0 (fix: 29.8.2-r0)
CVE-2026-63074: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-63074: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-75804: libcrypto3@3.5.7-r0
CVE-2026-75804: libssl3@3.5.7-r0
CVE-2026-75805: libcrypto3@3.5.7-r0
CVE-2026-75805: libssl3@3.5.7-r0
CVE-2026-75806: libcrypto3@3.5.7-r0
CVE-2026-75806: libssl3@3.5.7-r0
CVE-2026-88264: crun@1.28-r0 (fix: 1.30.1-r0)
CVE-2026-88265: crun@1.28-r0 (fix: 1.30.1-r0)
CVE-2026-89156: pcre2@10.47-r1 (fix: 10.48-r0)
CVE-2026-89158: pcre2@10.47-r1 (fix: 10.48-r0)
CVE-2026-89160: pcre2@10.47-r1 (fix: 10.48-r0)
CVE-2026-92542: docker-cli@29.5.3-r0 (fix: 29.8.2-r0)
GHSA-7236-3392-c5c6: github.com/moby/buildkit@v0.30.0 (fix: 0.31.1)
GHSA-mjcv-p78q-w5fw: github.com/moby/sys/user@v0.4.0 (fix: 0.4.1)
GHSA-xjvp-4fhw-gc47: github.com/opencontainers/runc@v1.4.2 (fix: 1.4.3)
GO-2026-5039: stdlib@go1.26.3 (fix: 1.25.11, 1.26.4)
GO-2026-5856: stdlib@go1.26.3 (fix: 1.25.12, 1.26.5, 1.27.0-rc.2)
GO-2026-5856: stdlib@go1.26.4 (fix: 1.25.12, 1.26.5, 1.27.0-rc.2)
GO-2026-6091: stdlib@go1.26.4 (fix: 1.25.13, 1.26.6, 1.27.0-rc.3)
GO-2026-6218: stdlib@go1.26.3 (fix: 1.25.13, 1.26.6, 1.27.0-rc.3)
GO-2026-6218: stdlib@go1.26.4 (fix: 1.25.13, 1.26.6, 1.27.0-rc.3)
Low
CVE-2022-3219: gnupg-dirmngr@2.4.9-r1
CVE-2022-3219: gnupg-gpgconf@2.4.9-r1
CVE-2022-3219: gnupg-keyboxd@2.4.9-r1
CVE-2022-3219: gpg-agent@2.4.9-r1
CVE-2022-3219: gpg@2.4.9-r1
CVE-2022-3219: gpgsm@2.4.9-r1
CVE-2026-35191: libcrypto3@3.5.7-r0
CVE-2026-35191: libssl3@3.5.7-r0
CVE-2026-54872: libcrypto3@3.5.7-r0
CVE-2026-54872: libssl3@3.5.7-r0
CVE-2026-54875: libcrypto3@3.5.7-r0
CVE-2026-54875: libssl3@3.5.7-r0
CVE-2026-77696: libcrypto3@3.5.7-r0
CVE-2026-77696: libssl3@3.5.7-r0
CVE-2026-89162: pcre2@10.47-r1 (fix: 10.48-r0)
Unknown
CVE-2026-53612: libblkid@2.42.1-r0 (fix: 2.42.3-r0)
CVE-2026-53612: libmount@2.42.1-r0 (fix: 2.42.3-r0)
CVE-2026-53613: libblkid@2.42.1-r0 (fix: 2.42.3-r0)
CVE-2026-53613: libmount@2.42.1-r0 (fix: 2.42.3-r0)
CVE-2026-53614: libblkid@2.42.1-r0 (fix: 2.42.3-r0)
CVE-2026-53614: libmount@2.42.1-r0 (fix: 2.42.3-r0)
GO-2026-5932: golang.org/x/crypto@v0.53.0
GO-2026-6599: stdlib@go1.26.4 (fix: 1.26.9, 1.27.2)
GO-2026-6600: stdlib@go1.26.4 (fix: 1.26.9, 1.27.2)
GO-2026-6603: golang.org/x/net@v0.56.0 (fix: 0.60.0)
GO-2026-6603: golang.org/x/net@v0.59.0 (fix: 0.60.0)
GO-2026-6603: stdlib@go1.26.3 (fix: 1.26.9)
GO-2026-6603: stdlib@go1.26.4 (fix: 1.26.9)
GO-2026-6604: stdlib@go1.26.4 (fix: 1.26.9, 1.27.2)
GO-2026-6605: stdlib@go1.26.3 (fix: 1.26.9, 1.27.2)
GO-2026-6605: stdlib@go1.26.4 (fix: 1.26.9, 1.27.2)
GO-2026-6607: stdlib@go1.26.3 (fix: 1.26.9, 1.27.2)
GO-2026-6607: stdlib@go1.26.4 (fix: 1.26.9, 1.27.2)
GO-2026-6608: stdlib@go1.26.3 (fix: 1.26.9, 1.27.2)
GO-2026-6608: stdlib@go1.26.4 (fix: 1.26.9, 1.27.2)
GO-2026-6609: stdlib@go1.26.4 (fix: 1.26.9, 1.27.2)
GO-2026-6610: stdlib@go1.26.3 (fix: 1.26.9)
GO-2026-6610: stdlib@go1.26.4 (fix: 1.26.9)
GO-2026-6611: golang.org/x/net@v0.56.0 (fix: 0.60.0)
GO-2026-6611: golang.org/x/net@v0.59.0 (fix: 0.60.0)
GO-2026-6611: stdlib@go1.26.3 (fix: 1.26.9)
GO-2026-6611: stdlib@go1.26.4 (fix: 1.26.9)
GO-2026-6612: golang.org/x/net@v0.56.0 (fix: 0.60.0)
GO-2026-6612: golang.org/x/net@v0.59.0 (fix: 0.60.0)
GO-2026-6612: stdlib@go1.26.3 (fix: 1.26.9)
GO-2026-6612: stdlib@go1.26.4 (fix: 1.26.9)
GO-2026-6613: stdlib@go1.26.3 (fix: 1.26.9, 1.27.2)
GO-2026-6613: stdlib@go1.26.4 (fix: 1.26.9, 1.27.2)
GO-2026-6617: golang.org/x/net@v0.56.0 (fix: 0.60.0)
GO-2026-6617: golang.org/x/net@v0.59.0 (fix: 0.60.0)
GO-2026-6617: stdlib@go1.26.3 (fix: 1.26.9)
GO-2026-6617: stdlib@go1.26.4 (fix: 1.26.9)

Remediation and SLA

  • SLA cadence: Critical findings are remediated or explicitly risk-accepted (by a maintainer) within 7 days; High within 30 days; every scanned image is rebuilt on a refreshed base image at least weekly. The daily scan runs gh aw compile --force-refresh-container-pins, so a pin-refresh PR is the default remediation step.
  • Status: Upstream — tracked only. These images are not built from a Dockerfile in github/gh-aw; a code-level fix cannot land here. Do not request a local patch PR. The daily pin refresh picks up upstream fixes once released.
  • Fixed versions: rows shown as pkg@installed => fixed list the fixed package version reported by Grype. The image release/digest containing each fix has not been confirmed from this scan; rows with no fix listed have no fixed package version reported.
  • Exceptions (not risk-accepted; pending maintainer approval): every finding above is awaiting a refreshed upstream image. Responsible project: the image's owning repository (see family summary). Next review: 2026-10-17 (weekly rebuild cadence).
  • Findings are ordered by severity (Critical, High, Medium, Low, Unknown); rows are unique ID pkg@version entries from the scan.

Generated by 🛡️ Daily Container Image Security Scan · copilot · auto · 190.8 AIC · ⌖ 0.9 AIC · ⊞ 8.5K · ◷

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions