Skip to content

golang.org/x/net v0.59.0 pulls in a known HTTP/2 DoS CVE batch, reachable via StreamableHTTPHandler.ServeHTTP #3469

Description

@SyedAnas01

Hi github-mcp-server maintainers,

I'm Syed Anas Mohiuddin, an independent security researcher doing a dependency audit across official MCP servers. This repo has a direct dependency on golang.org/x/net v0.59.0, affected by a known HTTP/2 DoS CVE batch (5 CVEs) fixed in v0.60.0.

Confirmed with govulncheck that the vulnerable code is actually called - reachable directly through the server's own HTTP/2 request path in pkg/http/server.go and pkg/http/handler.go's StreamableHTTPHandler.ServeHTTP.

There are also 6 Go-toolchain-level CVEs confirmed reachable here, which aren't fixed by a go.mod edit - they need rebuilding with a current Go toolchain (go1.27.2 or later) rather than a dependency bump.

Fix: bump golang.org/x/net to >=0.60.0, and rebuild/release with a current Go toolchain for the toolchain-level CVEs.

Filing as a public issue since these are already-public, assigned CVEs - purely a stale-dependency/toolchain flag, nothing sensitive to coordinate privately.

Thanks,
Anas

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions