GitHub MCP Server nil pointer dereference denial of service
GitHub MCP Server prior to version 1.1.0 is vulnerable to a denial of service attack due to improper nil checking in the CompletionsHandler function. An unauthenticated client can crash the server by sending a completion request with a missing or empty ref field.
Disclosed 28 July 2026 · Record updated 13 September 2026
Impact
Denial of service affecting the GitHub MCP Server before version 1.1.0
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-47427
