<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T15:58:02.735843+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-342159</id>
    <title>EUVD-2026-342159</title>
    <updated>2026-10-05T15:58:02.785074+00:00</updated>
    <content>EUVD-2026-342159</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-342159"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47427</id>
    <title>fkie_cve-2026-47427</title>
    <updated>2026-10-05T15:58:02.785113+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref without first checking whether it is nil, so a completion/complete request with a missing or empty ref field triggers a nil pointer dereference and a Go runtime panic; because the crash occurs before any authentication or token validation, any unauthenticated client able to send JSON-RPC messages can crash the server, resulting in a complete denial of service. This issue is fixed in version 1.1.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-47427"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w4q6-qw23-4rg7</id>
    <title>GHSA-w4q6-qw23-4rg7 — GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler</title>
    <updated>2026-10-05T15:58:02.785149+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/github/github-mcp-server</p>
<p>### Summary</p>
<p>A nil pointer dereference vulnerability in the GitHub MCP Server causes it to crash when receiving a malformed `completion/complete` request with missing or empty parameters. This allows any unauthenticated client to cause a complete denial of service.</p>
<p>### Details</p>
<p>The `CompletionsHandler` function in `pkg/github/server.go:198` accesses `params.Ref` without checking if it's nil first. When a client sends a `completion/complete` request with a missing `ref` field, the handler dereferences nil and the Go runtime panics.</p>
<p>The crash occurs before any authentication or token validation, so even requests with fake tokens can trigger it.</p>
<p>### PoC</p>
<p>After completing the MCP initialization handshake, send either:</p>
<p>**Empty params:**</p>
<p>{"jsonrpc":"2.0","id":2,"method":"completion/complete","params":{}}</p>
<p>**Missing ref field:**</p>
<p>{"jsonrpc":"2.0","id":2,"method":"completion/complete","params":{"argument":{"name":"x","value":"y"}}}</p>
<p>**Result:**</p>
<p>panic: runtime error: invalid memory address or nil pointer dereference
    goroutine 42 [running]:
    github.com/github/github-mcp-server/pkg/github.NewMCPServer.CompletionsHandler.func1(...)
        pkg/github/server.go:198 +0x24</p>
<p>### Impact</p>
<p>Any unauthenticated client that can send JSON-RPC messages to the server can crash it immediately. This is a complete denial of service - the panic is unrecoverable and kills the process.</p>
<p>Automated fuzzing with mcpsec found 108 crashes out of 925 test cases (11.7% crash rate).</p>
<p>###…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w4q6-qw23-4rg7"/>
  </entry>
</feed>
