GHSA-w4q6-qw23-4rg7: GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler
Summary
A nil pointer dereference vulnerability in the GitHub MCP Server causes it to crash when receiving a malformed completion/complete request with missing or empty parameters. This allows any unauthenticated client to cause a complete denial of service.
Details
The CompletionsHandler function in pkg/github/server.go:198 accesses params.Ref without checking if it's nil first. When a client sends a completion/complete request with a missing ref field, the handler dereferences nil and the Go runtime panics.
The crash occurs before any authentication or token validation, so even requests with fake tokens can trigger it.
PoC
After completing the MCP initialization handshake, send either:
Empty params:
{"jsonrpc":"2.0","id":2,"method":"completion/complete","params":{}}
Missing ref field:
{"jsonrpc":"2.0","id":2,"method":"completion/complete","params":{"argument":{"name":"x","value":"y"}}}
Result:
panic: runtime error: invalid memory address or nil pointer dereference
goroutine 42 [running]:
github.com/github/github-mcp-server/pkg/github.NewMCPServer.CompletionsHandler.func1(...)
pkg/github/server.go:198 +0x24
Impact
Any unauthenticated client that can send JSON-RPC messages to the server can crash it immediately. This is a complete denial of service - the panic is unrecoverable and kills the process.
Automated fuzzing with mcpsec found 108 crashes out of 925 test cases (11.7% crash rate).
Timeline
- Feb 21, 2026 - Initial report sent to opensource-security@github.com
- Mar 03, 2026 - Follow-up email sent, no response
- Mar 21, 2026 - Re-verified on v0.33.0, sent detailed report with PoC, no response
- Apr 06, 2026 - GHSA filed after 44 days without acknowledgment
Suggested Fix
func (s *Server) CompletionsHandler(ctx context.Context, params *mcp.CompleteParams) (*mcp.CompleteResult, error) {
if params == nil || params.Ref == nil {
return nil, fmt.Errorf("invalid request: missing ref parameter")
}
// ... rest of handler
}
Details
Original advisory: https://github.com/advisories/GHSA-w4q6-qw23-4rg7
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-474270.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-47427 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from GitHub Security Advisories
- mediumGHSA-jr6p-8pjj-mfx6: Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators s…2026-07-31
- mediumGHSA-68cj-mvg9-rgm2: Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing…2026-07-31
- mediumGHSA-ff84-5f28-78qj: re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex`…2026-07-31
- mediumGHSA-6hxr-mr5r-9836: re2: Global `String.prototype.match` with an empty-matchable pattern never advances → inf…2026-07-31
- mediumGHSA-x83g-979r-f5fh: Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII2026-07-31