Skip to content

[container-image-scan] Container findings for ghcr.io/github/github-mcp-server:v1.7.0 #49088

Description

@github-actions

Summary

Image: ghcr.io/github/github-mcp-server:v1.7.0

Severity Count
Critical 1
High 2
Medium 2
Low 0
Negligible 8
License violations 6

Remediation guidance

  • Upgrade to a newer github-mcp-server release that bundles patched Go/OS dependencies.
  • Review flagged Go module vulnerabilities and update go.mod pinned versions to the fixed releases below.
  • Review GPL/LGPL/MPL-licensed OS packages against the repository license policy.

Vulnerabilities

Click to expand 1C/2H/2M/0L/8N findings
error: [Critical] CVE-2026-5450: libc6@2.36-9+deb12u14
error: [High] CVE-2026-5435: libc6@2.36-9+deb12u14
error: [High] CVE-2026-5928: libc6@2.36-9+deb12u14
info: [Negligible] CVE-2010-4756: libc6@2.36-9+deb12u14
info: [Negligible] CVE-2018-20796: libc6@2.36-9+deb12u14
info: [Negligible] CVE-2019-1010022: libc6@2.36-9+deb12u14
info: [Negligible] CVE-2019-1010023: libc6@2.36-9+deb12u14
info: [Negligible] CVE-2019-1010024: libc6@2.36-9+deb12u14
info: [Negligible] CVE-2019-1010025: libc6@2.36-9+deb12u14
info: [Negligible] CVE-2019-9192: libc6@2.36-9+deb12u14
info: [Negligible] CVE-2025-27587: libssl3@3.0.20-1~deb12u2
warning: [Medium] CVE-2026-42767: libssl3@3.0.20-1~deb12u2
warning: [Medium] CVE-2026-6238: libc6@2.36-9+deb12u14

License violations

Click to expand 6 license findings
base-files@12.4+deb12u15 (GPL-2.0-or-later)
libc6@2.36-9+deb12u14 (GPL-2.0-only, HPND, LGPL-2.1-or-later, Spencer-94)
libssl3@3.0.20-1~deb12u2 (Artistic, GPL-1.0-only, GPL-1.0-or-later)
media-types@10.0.0 (ad-hoc)
netbase@6.4 (GPL-2.0-only)
tzdata@2026b-0+deb12u1 (public-domain)

Generated by 🛡️ Daily Container Image Security Scan · auto · 389.1 AIC · ⌖ 11.3 AIC · ⊞ 6.3K ·

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions