Hi github-mcp-server maintainers,
I'm Syed Anas Mohiuddin, an independent security researcher doing a dependency audit across official MCP servers. This repo has a direct dependency on golang.org/x/net v0.59.0, affected by a known HTTP/2 DoS CVE batch (5 CVEs) fixed in v0.60.0.
Confirmed with govulncheck that the vulnerable code is actually called - reachable directly through the server's own HTTP/2 request path in pkg/http/server.go and pkg/http/handler.go's StreamableHTTPHandler.ServeHTTP.
There are also 6 Go-toolchain-level CVEs confirmed reachable here, which aren't fixed by a go.mod edit - they need rebuilding with a current Go toolchain (go1.27.2 or later) rather than a dependency bump.
Fix: bump golang.org/x/net to >=0.60.0, and rebuild/release with a current Go toolchain for the toolchain-level CVEs.
Filing as a public issue since these are already-public, assigned CVEs - purely a stale-dependency/toolchain flag, nothing sensitive to coordinate privately.
Thanks,
Anas
Hi github-mcp-server maintainers,
I'm Syed Anas Mohiuddin, an independent security researcher doing a dependency audit across official MCP servers. This repo has a direct dependency on
golang.org/x/net v0.59.0, affected by a known HTTP/2 DoS CVE batch (5 CVEs) fixed in v0.60.0.Confirmed with
govulncheckthat the vulnerable code is actually called - reachable directly through the server's own HTTP/2 request path inpkg/http/server.goandpkg/http/handler.go'sStreamableHTTPHandler.ServeHTTP.There are also 6 Go-toolchain-level CVEs confirmed reachable here, which aren't fixed by a go.mod edit - they need rebuilding with a current Go toolchain (go1.27.2 or later) rather than a dependency bump.
Fix: bump
golang.org/x/netto>=0.60.0, and rebuild/release with a current Go toolchain for the toolchain-level CVEs.Filing as a public issue since these are already-public, assigned CVEs - purely a stale-dependency/toolchain flag, nothing sensitive to coordinate privately.
Thanks,
Anas