Skip to content

[container-image-scan] Container findings for ghcr.io/github/github-mcp-server #52450

Description

@github-actions

Summary

Image: ghcr.io/github/github-mcp-server:v1.9.0@sha256:881b53d6f75...

1 Critical, 3 High, 3 Medium, 1 Low, 7 Negligible vulnerabilities; 6 license policy violations.

Remediation

  • Rebase on a newer Debian 12 point release / bump libc6 and libssl3 to pick up glibc and OpenSSL security patches.
  • Update golang.org/x/text to >= 0.39.0 to fix GO-2026-5970.
  • Review GPL-2.0/Artistic-licensed base packages (libssl3, libc6, netbase, base-files) and the no licenses found/ad-hoc/public-domain items (tzdata, media-types) against the license policy; add explicit exceptions for unavoidable base-OS packages if acceptable.

Vulnerabilities

13 vulnerabilities across libc6, libssl3, golang.org/x/text
Severity ID Package Installed Fixed
Critical CVE-2026-5450 libc6 2.36-9+deb12u14 not specified
High GO-2026-5970 golang.org/x/text v0.37.0 0.39.0
High CVE-2026-5928 libc6 2.36-9+deb12u14 not specified
High CVE-2026-5435 libc6 2.36-9+deb12u14 not specified
Medium CVE-2026-42767 libssl3 3.0.20-1~deb12u2 not specified
Medium CVE-2026-6238 libc6 2.36-9+deb12u14 not specified
Medium CVE-2026-6791 libc6 2.36-9+deb12u14 not specified
Low CVE-2026-6368 libc6 2.36-9+deb12u14 not specified
Negligible CVE-2018-20796 libc6 2.36-9+deb12u14 not specified
Negligible CVE-2019-1010022 libc6 2.36-9+deb12u14 not specified
Negligible CVE-2019-1010023 libc6 2.36-9+deb12u14 not specified
Negligible CVE-2019-1010024 libc6 2.36-9+deb12u14 not specified
Negligible CVE-2019-1010025 libc6 2.36-9+deb12u14 not specified
Negligible CVE-2010-4756 libc6 2.36-9+deb12u14 not specified
Negligible CVE-2019-9192 libc6 2.36-9+deb12u14 not specified
Negligible CVE-2025-27587 libssl3 3.0.20-1~deb12u2 not specified

License Violations

6 rejected/unknown licenses
Package Version License(s)
tzdata 2026b-0+deb12u1 public-domain
netbase 6.4 GPL-2.0-only
libssl3 3.0.20-1~deb12u2 Artistic, GPL-1.0-only, GPL-1.0-or-later
media-types 10.0.0 ad-hoc
libc6 2.36-9+deb12u14 GPL-2.0-only, HPND, LGPL-2.1-or-later, Spencer-94
base-files 12.4+deb12u15 GPL-2.0-or-later

Generated by 🛡️ Daily Container Image Security Scan · auto · 327.5 AIC · ⌖ 10.6 AIC · ⊞ 6.5K ·

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions