CVE-2026-103111: pcre2@10.47-r1 (fix: 10.49-r0)
CVE-2026-14456: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-14456: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-14457: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-14457: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-17106: docker-cli@29.5.3-r0
CVE-2026-18798: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-18798: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-54873: libcrypto3@3.5.7-r0
CVE-2026-54873: libssl3@3.5.7-r0
CVE-2026-54874: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-54874: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-63072: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-63072: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-63075: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-63075: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-63076: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-63076: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
CVE-2026-72897: libcrypto3@3.5.7-r0
CVE-2026-72897: libssl3@3.5.7-r0
CVE-2026-76642: libblkid@2.42.1-r0 (fix: 2.42.3-r0)
CVE-2026-76642: libmount@2.42.1-r0 (fix: 2.42.3-r0)
CVE-2026-78408: libblkid@2.42.1-r0 (fix: 2.42.3-r1)
CVE-2026-78408: libmount@2.42.1-r0 (fix: 2.42.3-r1)
CVE-2026-78409: libblkid@2.42.1-r0 (fix: 2.42.3-r0)
CVE-2026-78409: libmount@2.42.1-r0 (fix: 2.42.3-r0)
CVE-2026-78410: libblkid@2.42.1-r0 (fix: 2.42.3-r0)
CVE-2026-78410: libmount@2.42.1-r0 (fix: 2.42.3-r0)
CVE-2026-84042: crun@1.28-r0 (fix: 1.30.1-r0)
CVE-2026-84782: libcrypto3@3.5.7-r0
CVE-2026-84782: libssl3@3.5.7-r0
CVE-2026-84784: libcrypto3@3.5.7-r0
CVE-2026-84784: libssl3@3.5.7-r0
CVE-2026-85091: zlib@1.3.2-r0 (fix: 1.3.2-r1)
CVE-2026-86145: pcre2@10.47-r1 (fix: 10.48-r0)
CVE-2026-89157: pcre2@10.47-r1 (fix: 10.48-r0)
CVE-2026-89161: pcre2@10.47-r1 (fix: 10.48-r0)
CVE-2026-92543: docker-cli@29.5.3-r0 (fix: 29.8.2-r0)
GHSA-2v4p-qf9q-27wj: google.golang.org/grpc@v1.81.1 (fix: 1.82.2)
GHSA-f5mr-q85p-6hh6: github.com/sigstore/fulcio@v1.8.5 (fix: 1.8.6)
GHSA-hfg8-hc9c-6c3h: github.com/moby/go-archive@v0.2.0 (fix: 0.3.0)
GHSA-hrxh-6v49-42gf: google.golang.org/grpc@v1.81.1 (fix: 1.82.1)
GHSA-vp52-pcj8-j9qc: google.golang.org/grpc@v1.81.1 (fix: 1.83.1)
GO-2026-4970: stdlib@go1.26.4 (fix: 1.25.12, 1.26.5, 1.27.0-rc.2)
GO-2026-5026: stdlib@go1.26.3 (fix: 1.25.13, 1.26.6, 1.27.0-rc.3)
GO-2026-5026: stdlib@go1.26.4 (fix: 1.25.13, 1.26.6, 1.27.0-rc.3)
GO-2026-5037: stdlib@go1.26.3 (fix: 1.25.11, 1.26.4)
GO-2026-5942: stdlib@go1.26.3 (fix: 1.26.6, 1.27.0-rc.3)
GO-2026-5942: stdlib@go1.26.4 (fix: 1.26.6, 1.27.0-rc.3)
GO-2026-5970: golang.org/x/text@v0.38.0 (fix: 0.39.0)
GO-2026-5972: stdlib@go1.26.3 (fix: 1.25.13, 1.26.6, 1.27.0-rc.3)
GO-2026-5972: stdlib@go1.26.4 (fix: 1.25.13, 1.26.6, 1.27.0-rc.3)
GO-2026-6089: stdlib@go1.26.4 (fix: 1.25.13, 1.26.6, 1.27.0-rc.3)
GO-2026-6090: stdlib@go1.26.3 (fix: 1.25.13, 1.26.6, 1.27.0-rc.3)
GO-2026-6090: stdlib@go1.26.4 (fix: 1.25.13, 1.26.6, 1.27.0-rc.3)
GO-2026-6354: golang.org/x/crypto@v0.53.0 (fix: 0.56.0)
GO-2026-6355: golang.org/x/crypto@v0.53.0 (fix: 0.56.0)
MCP Gateway scan summary
Status: Upstream (owned by
github/gh-aw-mcpg). Unique finding rows: 4 Critical, 57 High, 33 Medium, 15 Low, 37 Unknown; 0 license violations.Images
ghcr.io/github/gh-aw-mcpg:v0.4.30@sha256:ab5a436a1490438db473e4e3d4c973cb1d75e3cb233fb08b73d31b42d7d18fbaFindings by severity
Critical
High
Medium
Low
Unknown
Remediation and SLA
gh aw compile --force-refresh-container-pins, so a pin-refresh PR is the default remediation step.github/gh-aw; a code-level fix cannot land here. Do not request a local patch PR. The daily pin refresh picks up upstream fixes once released.pkg@installed => fixedlist the fixed package version reported by Grype. The image release/digest containing each fix has not been confirmed from this scan; rows with no fix listed have no fixed package version reported.ID pkg@versionentries from the scan.