[container-image-scan] Container findings for ghcr.io/github/github-mcp-server:v1.8.0
- Dominant language
- Go
- Stars
- 5.1k
- Forks
- 541
- Avg merge
- 5h 46m
- Merged PRs (30d)
- 760
Description
### Summary
**Image:** `ghcr.io/github/github-mcp-server:v1.8.0`
**Pinned reference:** `ghcr.io/github/github-mcp-server:v1.8.0@sha256:d5a18c04b92714c309eb46a2305087e91a4dbd80420f6e462656699f95093520`
- Vulnerabilities: 1 Critical, 3 High, 2 Medium, 8 Negligible
- License policy violations: 6
#### Vulnerabilities
1 Critical, 3 High (expand for full list)
- **[Critical] CVE-2026-5450** — `libc6@2.36-9+deb12u14` — no fix available yet. (securitytracker.debian.org/redacted)
- **[High] CVE-2026-5928** — `libc6@2.36-9+deb12u14` — no fix available yet. (securitytracker.debian.org/redacted)
- **[High] CVE-2026-5435** — `libc6@2.36-9+deb12u14` — no fix available yet. (securitytracker.debian.org/redacted)
- **[High] GO-2026-5970** — `golang.org/x/text@v0.37.0` — fix: `0.39.0`. https://go.dev/issue/80142
2 Medium, 8 Negligible (expand for full list)
- **[Medium] CVE-2026-42767** — `libssl3@3.0.20-1~deb12u2` — no fix available yet.
- **[Medium] CVE-2026-6238** — `libc6@2.36-9+deb12u14` — no fix available yet.
- **[Negligible] CVE-2010-4756** — `libc6@2.36-9+deb12u14`
- **[Negligible] CVE-2018-20796** — `libc6@2.36-9+deb12u14`
- **[Negligible] CVE-2019-1010022** — `libc6@2.36-9+deb12u14`
- **[Negligible] CVE-2019-1010023** — `libc6@2.36-9+deb12u14`
- **[Negligible] CVE-2019-1010024** — `libc6@2.36-9+deb12u14`
- **[Negligible] CVE-2019-1010025** — `libc6@2.36-9+deb12u14`
- **[Negligible] CVE-2019-9192** — `libc6@2.36-9+deb12u14`
- **[Negligible] CVE-2025-27587** — `libssl3@3.0.20-1~deb12u2`
#### Licenses
6 rejected/unknown license findings
- `base-files@12.4+deb12u15` — GPL-2.0-or-later
- `libssl3@3.0.20-1~deb12u2` — Artistic, GPL-1.0-only, GPL-1.0-or-later
- `tzdata@2026b-0+deb12u1` — public-domain
- `libc6@2.36-9+deb12u14` — GPL-2.0-only, HPND, LGPL-2.1-or-later, Spencer-94
- `media-types@10.0.0` — ad-hoc
- `netbase@6.4` — GPL-2.0-only
#### Remediation
- Rebuild the `github-mcp-server` image on top of a patched Debian base (`libc6` >= a version fixing CVE-2026-5450/5928/5435) once upstream releases updated packages; track glibc security advisories.
- Bump the Go module `golang.org/x/text` to `v0.39.0` or later to resolve GO-2026-5970.
- Review GPL/Artistic-licensed base packages (`base-files`, `libssl3`, `libc6`, `netbase`) against organizational license policy; these are typically unavoidable in Debian-based images but should be explicitly allow-listed if acceptable.
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/31242183814) · auto · 434.8 AIC · ⌖ 3.45 AIC · ⊞ 6.5K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
Contributor guide
Assessment
This issue has not been assessed yet.