Overview
Image: ghcr.io/github/github-mcp-server:v1.9.0 — pinned reference:
ghcr.io/github/github-mcp-server:v1.9.0@sha256:881b53d6f75f69bdbc1b5b10fc2f1361717c19054143b3a8529fb5c32061a50e
Grype found: 1 Critical, 3 High, 3 Medium, 1 Low, 8 Negligible across 40 packages. Grant found 6 license policy violations.
Key metrics
| Severity |
Count |
| Critical |
1 |
| High |
3 |
| Medium |
3 |
| Low |
1 |
| Negligible |
8 |
Critical vulnerability
| CVE |
Package |
Installed |
Fixed |
| CVE-2026-5450 |
libc6 |
2.36-9+deb12u14 |
(no fix listed) |
High vulnerabilities
| CVE/Advisory |
Package |
Installed |
Fixed |
| GO-2026-5970 |
golang.org/x/text |
v0.37.0 |
v0.39.0 |
| CVE-2026-5928 |
libc6 |
2.36-9+deb12u14 |
(no fix listed) |
| CVE-2026-5435 |
libc6 |
2.36-9+deb12u14 |
(no fix listed) |
Medium / Low / Negligible vulnerabilities
3 Medium, 1 Low, 8 Negligible findings
Remaining findings are lower-severity Debian base package (libc6 family, libssl3) advisories. See raw scan log at /tmp/gh-aw/agent/image-scan/compile-output.txt (grep github-mcp-server:v1.9.0) for full detail.
License policy violations
All 6 violations
| Package |
Version |
License |
| base-files |
12.4+deb12u15 |
GPL-2.0-or-later |
| libc6 |
2.36-9+deb12u14 |
GPL-2.0-only / HPND / LGPL-2.1-or-later / Spencer-94 |
| netbase |
6.4 |
GPL-2.0-only |
| libssl3 |
3.0.20-1~deb12u2 |
Artistic / GPL-1.0-only / GPL-1.0-or-later |
| media-types |
10.0.0 |
ad-hoc |
| tzdata |
2026b-0+deb12u1 |
public-domain |
Remediation
libc6 (glibc) CVE-2026-5450/5928/5435 currently have no fixed version upstream from Debian — track for a patched libc6 release and rebuild once available; consider risk-accepting in the interim per the 7-day Critical SLA if no fix is imminent.
- Bump
golang.org/x/text to >=v0.39.0 to resolve the High GO-2026-5970 advisory (requires rebuilding the Go binary with the updated module).
- Review Grant license policy allow-list for the 6 Debian base-package licenses (GPL/Artistic/public-domain) if intentionally accepted.
- Daily
--force-refresh-container-pins run will pick up any future glibc/Debian base patch automatically.
Generated by 🛡️ Daily Container Image Security Scan · auto · 295.8 AIC · ⌖ 10.1 AIC · ⊞ 6.9K · ◷
Overview
Image:
ghcr.io/github/github-mcp-server:v1.9.0— pinned reference:ghcr.io/github/github-mcp-server:v1.9.0@sha256:881b53d6f75f69bdbc1b5b10fc2f1361717c19054143b3a8529fb5c32061a50eGrype found: 1 Critical, 3 High, 3 Medium, 1 Low, 8 Negligible across 40 packages. Grant found 6 license policy violations.
Key metrics
Critical vulnerability
High vulnerabilities
Medium / Low / Negligible vulnerabilities
3 Medium, 1 Low, 8 Negligible findings
Remaining findings are lower-severity Debian base package (
libc6family,libssl3) advisories. See raw scan log at/tmp/gh-aw/agent/image-scan/compile-output.txt(grepgithub-mcp-server:v1.9.0) for full detail.License policy violations
All 6 violations
Remediation
libc6(glibc) CVE-2026-5450/5928/5435 currently have no fixed version upstream from Debian — track for a patchedlibc6release and rebuild once available; consider risk-accepting in the interim per the 7-day Critical SLA if no fix is imminent.golang.org/x/textto >=v0.39.0 to resolve the High GO-2026-5970 advisory (requires rebuilding the Go binary with the updated module).--force-refresh-container-pinsrun will pick up any future glibc/Debian base patch automatically.