Skip to content

[container-image-scan] Container findings for ghcr.io/github/github-mcp-server:v1.7.0 #49088

Description

@github-actions

Summary

Image: ghcr.io/github/github-mcp-server:v1.7.0

Severity Count
Critical 1
High 2
Medium 2
Low 0
Negligible 8
License violations 6

Remediation guidance

  • Upgrade to a newer github-mcp-server release that bundles patched Go/OS dependencies.
  • Review flagged Go module vulnerabilities and update go.mod pinned versions to the fixed releases below.
  • Review GPL/LGPL/MPL-licensed OS packages against the repository license policy.

Vulnerabilities

Click to expand 1C/2H/2M/0L/8N findings
error: [Critical] CVE-2026-5450: libc6@2.36-9+deb12u14
error: [High] CVE-2026-5435: libc6@2.36-9+deb12u14
error: [High] CVE-2026-5928: libc6@2.36-9+deb12u14
info: [Negligible] CVE-2010-4756: libc6@2.36-9+deb12u14
info: [Negligible] CVE-2018-20796: libc6@2.36-9+deb12u14
info: [Negligible] CVE-2019-1010022: libc6@2.36-9+deb12u14
info: [Negligible] CVE-2019-1010023: libc6@2.36-9+deb12u14
info: [Negligible] CVE-2019-1010024: libc6@2.36-9+deb12u14
info: [Negligible] CVE-2019-1010025: libc6@2.36-9+deb12u14
info: [Negligible] CVE-2019-9192: libc6@2.36-9+deb12u14
info: [Negligible] CVE-2025-27587: libssl3@3.0.20-1~deb12u2
warning: [Medium] CVE-2026-42767: libssl3@3.0.20-1~deb12u2
warning: [Medium] CVE-2026-6238: libc6@2.36-9+deb12u14

License violations

Click to expand 6 license findings
base-files@12.4+deb12u15 (GPL-2.0-or-later)
libc6@2.36-9+deb12u14 (GPL-2.0-only, HPND, LGPL-2.1-or-later, Spencer-94)
libssl3@3.0.20-1~deb12u2 (Artistic, GPL-1.0-only, GPL-1.0-or-later)
media-types@10.0.0 (ad-hoc)
netbase@6.4 (GPL-2.0-only)
tzdata@2026b-0+deb12u1 (public-domain)

Generated by 🛡️ Daily Container Image Security Scan · auto · 389.1 AIC · ⌖ 11.3 AIC · ⊞ 6.3K ·

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions