{"id":"CVE-2026-47427","aliases":["GHSA-w4q6-qw23-4rg7"],"title":"GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler","summary":"GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler","severity":"high","cvss":7.5,"cwe":["CWE-476"],"vendor":"github","product":"github.com/github/github-mcp-server","ecosystem":"go","affected":["github.com/github/github-mcp-server < 1.1.0"],"patched":["github.com/github/github-mcp-server 1.1.0"],"published":"2026-07-28","updated":"2026-07-28","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-w4q6-qw23-4rg7","references":[{"url":"https://github.com/github/github-mcp-server/security/advisories/GHSA-w4q6-qw23-4rg7"},{"url":"https://github.com/github/github-mcp-server/pull/2502"},{"url":"https://github.com/github/github-mcp-server/commit/c88d2ecdd3bb07f7bdd75296e3ee676febf14f58"},{"url":"https://github.com/github/github-mcp-server/releases/tag/v1.1.0"},{"url":"https://github.com/advisories/GHSA-w4q6-qw23-4rg7"}],"tags":["ghsa","go"],"ingestedAt":"2026-07-28T14:36:39.050Z","epss":0.00442,"epssPercentile":0.37682,"slug":"CVE-2026-47427","body":"## Overview\n\n### Summary\n\nA nil pointer dereference vulnerability in the GitHub MCP Server causes it to crash when receiving a malformed `completion/complete` request with missing or empty parameters. This allows any unauthenticated client to cause a complete denial of service.\n\n### Details\n\nThe `CompletionsHandler` function in `pkg/github/server.go:198` accesses `params.Ref` without checking if it's nil first. When a client sends a `completion/complete` request with a missing `ref` field, the handler dereferences nil and the Go runtime panics.\n\nThe crash occurs before any authentication or token validation, so even requests with fake tokens can trigger it.\n\n### PoC\n\nAfter completing the MCP initialization handshake, send either:\n\n**Empty params:**\n\n    {\"jsonrpc\":\"2.0\",\"id\":2,\"method\":\"completion/complete\",\"params\":{}}\n\n**Missing ref field:**\n\n    {\"jsonrpc\":\"2.0\",\"id\":2,\"method\":\"completion/complete\",\"params\":{\"argument\":{\"name\":\"x\",\"value\":\"y\"}}}\n\n**Result:**\n\n    panic: runtime error: invalid memory address or nil pointer dereference\n    goroutine 42 [running]:\n    github.com/github/github-mcp-server/pkg/github.NewMCPServer.CompletionsHandler.func1(...)\n        pkg/github/server.go:198 +0x24\n\n### Impact\n\nAny unauthenticated client that can send JSON-RPC messages to the server can crash it immediately. This is a complete denial of service - the panic is unrecoverable and kills the process.\n\nAutomated fuzzing with mcpsec found 108 crashes out of 925 test cases (11.7% crash rate).\n\n### Timeline\n\n- **Feb 21, 2026** - Initial report sent to opensource-security@github.com\n- **Mar 03, 2026** - Follow-up email sent, no response\n- **Mar 21, 2026** - Re-verified on v0.33.0, sent detailed report with PoC, no response\n- **Apr 06, 2026** - GHSA filed after 44 days without acknowledgment\n\n### Suggested Fix\n\n    func (s *Server) CompletionsHandler(ctx context.Context, params *mcp.CompleteParams) (*mcp.CompleteResult, error) {\n        if params == nil || params.Ref == nil {\n            return nil, fmt.Errorf(\"invalid request: missing ref parameter\")\n        }\n        // ... rest of handler\n    }\n\n## Affected packages\n\n- `github.com/github/github-mcp-server < 1.1.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/github/github-mcp-server 1.1.0`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}