Skip to content

[container-image-scan] Container findings for ghcr.io/github/github-mcp-server:v1.8.0 #51328

Description

@github-actions

Summary

Image: ghcr.io/github/github-mcp-server:v1.8.0
Pinned reference: ghcr.io/github/github-mcp-server:v1.8.0@sha256:d5a18c04b92714c309eb46a2305087e91a4dbd80420f6e462656699f95093520

  • Vulnerabilities: 1 Critical, 3 High, 2 Medium, 8 Negligible
  • License policy violations: 6

Vulnerabilities

1 Critical, 3 High (expand for full list)
  • [Critical] CVE-2026-5450libc6@2.36-9+deb12u14 — no fix available yet. (securitytracker.debian.org/redacted)
  • [High] CVE-2026-5928libc6@2.36-9+deb12u14 — no fix available yet. (securitytracker.debian.org/redacted)
  • [High] CVE-2026-5435libc6@2.36-9+deb12u14 — no fix available yet. (securitytracker.debian.org/redacted)
  • [High] GO-2026-5970golang.org/x/text@v0.37.0 — fix: 0.39.0. https://go.dev/issue/80142
2 Medium, 8 Negligible (expand for full list)

Licenses

6 rejected/unknown license findings
  • base-files@12.4+deb12u15 — GPL-2.0-or-later
  • libssl3@3.0.20-1~deb12u2 — Artistic, GPL-1.0-only, GPL-1.0-or-later
  • tzdata@2026b-0+deb12u1 — public-domain
  • libc6@2.36-9+deb12u14 — GPL-2.0-only, HPND, LGPL-2.1-or-later, Spencer-94
  • media-types@10.0.0 — ad-hoc
  • netbase@6.4 — GPL-2.0-only

Remediation

  • Rebuild the github-mcp-server image on top of a patched Debian base (libc6 >= a version fixing CVE-2026-5450/5928/5435) once upstream releases updated packages; track glibc security advisories.
  • Bump the Go module golang.org/x/text to v0.39.0 or later to resolve GO-2026-5970.
  • Review GPL/Artistic-licensed base packages (base-files, libssl3, libc6, netbase) against organizational license policy; these are typically unavoidable in Debian-based images but should be explicitly allow-listed if acceptable.

Generated by 🛡️ Daily Container Image Security Scan · auto · 434.8 AIC · ⌖ 3.45 AIC · ⊞ 6.5K ·

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions