Answer in brief
CVE-2026-47427 records a High severity tool poisoning vulnerability in GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler. The source record does not mark it as known exploited. 1 affected package is mapped in the feed.
Answer in brief
CVE-2026-47427 records a High severity tool poisoning vulnerability in GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler. The source record does not mark it as known exploited. 1 affected package is mapped in the feed.
Update github.com/github/github-mcp-server to 1.1.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanTool Poisoning describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2026-47427 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| github.com/github/github-mcp-servergo | <1.1.0 | 1.1.0 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
CVE-2026-47427 records a High severity tool poisoning vulnerability in GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler. The source record does not mark it as known exploited. 1 affected package is mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for github.com/github/github-mcp-server.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardUpdate github.com/github/github-mcp-server to 1.1.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanTool Poisoning describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2026-47427 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| github.com/github/github-mcp-servergo | <1.1.0 | 1.1.0 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
CVE-2026-47427 records a High severity tool poisoning vulnerability in GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler. The source record does not mark it as known exploited. 1 affected package is mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for github.com/github/github-mcp-server.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard### Summary A nil pointer dereference vulnerability in the GitHub MCP Server causes it to crash when receiving a malformed `completion/complete` request with missing or empty parameters. This allows any unauthenticated client to cause a complete denial of service. ### Details The `CompletionsHandler` function in `pkg/github/server.go:198` accesses `params.Ref` without checking if it's nil first. When a client sends a `completion/complete` request with a missing `ref` field, the handler dereferences nil and the Go runtime panics. The crash occurs before any authentication or token validation, so even requests with fake tokens can trigger it. ### PoC After completing the MCP initialization handshake, send either: **Empty params:** {"jsonrpc":"2.0","id":2,"method":"completion/complete","params":{}} **Missing ref field:** {"jsonrpc":"2.0","id":2,"method":"completion/complete","params":{"argument":{"name":"x","value":"y"}}} **Result:** panic: runtime error: invalid memory address or nil pointer dereference goroutine 42 [running]: github.com/github/github-mcp-server/pkg/github.NewMCPServer.CompletionsHandler.func1(...) pkg/github/server.go:198 +0x24 ### Impact Any unauthenticated client that can send JSON-RPC messages to the server can crash it immediately. This is a complete denial of service - the panic is unrecoverable and kills the process. Automated fuzzing with mcpsec found 108 crashes out of 925 test cases (11.7% crash rate). ### Timeline - **Feb 21, 2026** - Initial report sent to [email protected] - **Mar 03, 2026** - Follow-up email sent, no response - **Mar 21, 2026** - Re-verified on v0.33.0, sent detailed report with PoC, no response - **Apr 06, 2026** - GHSA filed after 44 days without acknowledgment ### Suggested Fix func (s *Server) CompletionsHandler(ctx context.Context, params *mcp.CompleteParams) (*mcp.CompleteResult, error) { if params == nil || params.Ref == nil { return nil, fmt.Errorf("invalid request: missing ref parameter") } // ... rest of handler }
### Summary A nil pointer dereference vulnerability in the GitHub MCP Server causes it to crash when receiving a malformed `completion/complete` request with missing or empty parameters. This allows any unauthenticated client to cause a complete denial of service. ### Details The `CompletionsHandler` function in `pkg/github/server.go:198` accesses `params.Ref` without checking if it's nil first. When a client sends a `completion/complete` request with a missing `ref` field, the handler dereferences nil and the Go runtime panics. The crash occurs before any authentication or token validation, so even requests with fake tokens can trigger it. ### PoC After completing the MCP initialization handshake, send either: **Empty params:** {"jsonrpc":"2.0","id":2,"method":"completion/complete","params":{}} **Missing ref field:** {"jsonrpc":"2.0","id":2,"method":"completion/complete","params":{"argument":{"name":"x","value":"y"}}} **Result:** panic: runtime error: invalid memory address or nil pointer dereference goroutine 42 [running]: github.com/github/github-mcp-server/pkg/github.NewMCPServer.CompletionsHandler.func1(...) pkg/github/server.go:198 +0x24 ### Impact Any unauthenticated client that can send JSON-RPC messages to the server can crash it immediately. This is a complete denial of service - the panic is unrecoverable and kills the process. Automated fuzzing with mcpsec found 108 crashes out of 925 test cases (11.7% crash rate). ### Timeline - **Feb 21, 2026** - Initial report sent to [email protected] - **Mar 03, 2026** - Follow-up email sent, no response - **Mar 21, 2026** - Re-verified on v0.33.0, sent detailed report with PoC, no response - **Apr 06, 2026** - GHSA filed after 44 days without acknowledgment ### Suggested Fix func (s *Server) CompletionsHandler(ctx context.Context, params *mcp.CompleteParams) (*mcp.CompleteResult, error) { if params == nil || params.Ref == nil { return nil, fmt.Errorf("invalid request: missing ref parameter") } // ... rest of handler }