CVE-2026-47427Patch(github / mcp_server)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch github mcp_server systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref without first checking whether it is nil, so a completion/complete request with a missing or empty ref field triggers a nil pointer dereference and a Go runtime panic; because the crash occurs before any authentication or token validation, any unauthenticated client able to send JSON-RPC messages can crash the server, resulting in a complete denial of service. This issue is fixed in version 1.1.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mcp_server

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-04); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
mcp_server

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-08-01: 1Mentions · 2026-08-04: 2Mentions · 2026-08-09: 1PoC Mentioned / Linked · 2026-08-04: 2Patch / Workaround · 2026-08-01: 1Patch / Workaround · 2026-08-04: 1Patch / Workaround · 2026-08-09: 1Technical Details · 2026-08-01: 1Technical Details · 2026-08-04: 2Technical Details · 2026-08-09: 108-0108-0408-09
Signal classification3 categories
Patch
250.0%
PoC
125.0%
Disclosure
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-011
Patch1
2026-08-042
Patch1PoC1
2026-08-091
Disclosure1
Full discourse4 posts
  • Manthan Ghasadiya@g_m_j_2703
    PoC

    Got my 4th CVE published this month: CVE-2026-47427 Unauthenticated DoS in GitHub's official MCP server. One malformed request crashes the whole server. No auth needed. Here's how it works: https://t.co/IR3h23cgFq

    Post summary

    The tweet announces CVE‑2026‑47427, a unauthenticated DoS affecting GitHub’s MCP server, and points to a link that presumably demonstrates how the vulnerability can be triggered.

    11030311
    144 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    CVE-2026-47427 - Unauthenticated DoS in GitHub MCP Server before 1.1.0. Nil pointer dereference crashes server. CVSS 7.5. Update to 1.1.0 immediately. #CVE #GitHub #infosec #redteam #blueteam #cybersecurity #devsecops #devops #developer #gitlab #git #cybersecuritytips #cybersecuritynews https://www.valtersit.com/cve/CVE-2026-47427

    Post summary

    The tweet highlights the CVE-2026-47427 DoS vulnerability in GitHub MCP Server and urges users to patch to version 1.1.0 immediately.

    10011216
    978 followersView on X
  • Manthan Ghasadiya@g_m_j_2703
    Patch

    Credit to @SamMorrowDrums on the GitHub MCP team for picking up the report, assigning the CVE, and shipping the fix in PR #2502. Same lesson I keep hitting across MCP servers: agent tooling ships fast, basic validation gets skipped. A missing nil check becomes a remote crash. Writeup: http://github.com/manthanghasadiya/writeups/tree/main/CVE-2026-47427 More coming.

    Post summary

    CVE-2026-47427 was discovered, a fix was committed in PR #2502, and a detailed write‑up is linked. No exploit code or active exploitation is reported.

    0002051
    144 followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    🤖 GitHub's official MCP Server vulnerable to unauthenticated DoS CVE-2026-47427 A malformed JSON-RPC completion request can trigger a nil-pointer panic before authentication occurs, allowing a reachable unauthenticated client to crash the MCP server. ✅ Fixed: 1.1.0 🔎 Source: GitHub / Tenable #GitHub #MCP #AISecurity #DoS #CVE

    Post summary

    The GitHub MCP Server is vulnerable to an unauthenticated DoS caused by a malformed JSON‑RPC request that triggers a nil‑pointer panic; patch 1.1.0 addresses the issue.

    0000051
    34 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgithubmcp_server---

Explore more