Skip to content

[container-image-scan] GitHub MCP Server CVE burn-down #65794

Description

@github-actions

GitHub MCP Server scan summary

Status: Upstream (owned by github/github-mcp-server). Unique finding rows: 1 Critical, 5 High, 14 Medium, 5 Low, 11 Unknown; 0 license violations.

Images

Image Pinned reference Status
github-mcp-server ghcr.io/github/github-mcp-server:v1.12.2@sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6 upstream

Findings by severity

Critical
CVE-2026-75803: libssl3@3.0.20-1~deb12u2 (fix: 3.0.22-1~deb12u1)
High
CVE-2026-19499: libc6@2.36-9+deb12u14
CVE-2026-54874: libssl3@3.0.20-1~deb12u2 (fix: 3.0.22-1~deb12u1)
CVE-2026-63072: libssl3@3.0.20-1~deb12u2 (fix: 3.0.22-1~deb12u1)
CVE-2026-63076: libssl3@3.0.20-1~deb12u2 (fix: 3.0.22-1~deb12u1)
CVE-2026-84782: libssl3@3.0.20-1~deb12u2
Medium
CVE-2026-18374: libc6@2.36-9+deb12u14
CVE-2026-19542: libc6@2.36-9+deb12u14
CVE-2026-35189: libssl3@3.0.20-1~deb12u2
CVE-2026-42767: libssl3@3.0.20-1~deb12u2 (fix: 3.0.22-1~deb12u1)
CVE-2026-6238: libc6@2.36-9+deb12u14
CVE-2026-63074: libssl3@3.0.20-1~deb12u2 (fix: 3.0.22-1~deb12u1)
CVE-2026-6791: libc6@2.36-9+deb12u14
CVE-2026-75805: libssl3@3.0.20-1~deb12u2
CVE-2026-75806: libssl3@3.0.20-1~deb12u2
CVE-2026-77117: libc6@2.36-9+deb12u14
CVE-2026-80489: libc6@2.36-9+deb12u14
CVE-2026-8674: libc6@2.36-9+deb12u14
CVE-2026-86805: libc6@2.36-9+deb12u14
CVE-2026-89092: libc6@2.36-9+deb12u14
Low
CVE-2026-54872: libssl3@3.0.20-1~deb12u2
CVE-2026-6368: libc6@2.36-9+deb12u14
CVE-2026-77696: libssl3@3.0.20-1~deb12u2
CVE-2026-95818: libc6@2.36-9+deb12u14
CVE-2026-97399: libc6@2.36-9+deb12u14
Unknown
GO-2026-6599: stdlib@go1.27.1 (fix: 1.26.9, 1.27.2)
GO-2026-6600: stdlib@go1.27.1 (fix: 1.26.9, 1.27.2)
GO-2026-6603: stdlib@go1.27.1 (fix: 1.27.2)
GO-2026-6605: stdlib@go1.27.1 (fix: 1.26.9, 1.27.2)
GO-2026-6607: stdlib@go1.27.1 (fix: 1.26.9, 1.27.2)
GO-2026-6608: stdlib@go1.27.1 (fix: 1.26.9, 1.27.2)
GO-2026-6610: stdlib@go1.27.1 (fix: 1.27.2)
GO-2026-6611: stdlib@go1.27.1 (fix: 1.27.2)
GO-2026-6612: stdlib@go1.27.1 (fix: 1.27.2)
GO-2026-6613: stdlib@go1.27.1 (fix: 1.26.9, 1.27.2)
GO-2026-6617: stdlib@go1.27.1 (fix: 1.27.2)

Remediation and SLA

  • SLA cadence: Critical findings are remediated or explicitly risk-accepted (by a maintainer) within 7 days; High within 30 days; every scanned image is rebuilt on a refreshed base image at least weekly. The daily scan runs gh aw compile --force-refresh-container-pins, so a pin-refresh PR is the default remediation step.
  • Status: Upstream — tracked only. These images are not built from a Dockerfile in github/gh-aw; a code-level fix cannot land here. Do not request a local patch PR. The daily pin refresh picks up upstream fixes once released.
  • Fixed versions: rows shown as pkg@installed => fixed list the fixed package version reported by Grype. The image release/digest containing each fix has not been confirmed from this scan; rows with no fix listed have no fixed package version reported.
  • Exceptions (not risk-accepted; pending maintainer approval): every finding above is awaiting a refreshed upstream image. Responsible project: the image's owning repository (see family summary). Next review: 2026-10-17 (weekly rebuild cadence).
  • Findings are ordered by severity (Critical, High, Medium, Low, Unknown); rows are unique ID pkg@version entries from the scan.

Generated by 🛡️ Daily Container Image Security Scan · copilot · auto · 190.8 AIC · ⌖ 0.9 AIC · ⊞ 8.5K · ◷

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions