CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-w4q6-qw23-4rg7: GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler

highCVSS 7.5CVE-2026-47427
Summary A nil pointer dereference vulnerability in the GitHub MCP Server causes it to crash when receiving a malformed completion/complete request with missing or empty parameters. This allows any unauthenticated client to cause a complete denial of service. Details The CompletionsHandler function in pkg/github/server.go:198 accesses params.Ref without checking if it's nil first. When a client sends a completion/complete request with a missing ref field, the handler dereferences nil and the Go runtime panics. The crash occurs before any authentication or token validation, so even requests with fake tokens can trigger it. PoC After completing the MCP initialization handshake, send either: Empty params: {"jsonrpc":"2.0","id":2,"method":"completion/complete","params":{}} Missing ref field: {"jsonrpc":"2.0","id":2,"method":"completion/complete","params":{"argument":{"name":"x","value":"y"}}} Result: panic: runtime error: invalid memory address or nil pointer dereference goroutine 42 [running]: github.com/github/github-mcp-server/pkg/github.NewMCPServer.CompletionsHandler.func1(...) pkg/github/server.go:198 +0x24 Impact Any unauthenticated client that can send JSON-RPC messages to the server can crash it immediately. This is a complete denial of service - the panic is unrecoverable and kills the process. Automated fuzzing with mcpsec found 108 crashes out of 925 test cases (11.7% crash rate). Timeline - Feb 21, 2026 - Initial report sent to opensource-security@github.com - Mar 03, 2026 - Follow-up email sent, no response - Mar 21, 2026 - Re-verified on v0.33.0, sent detailed report with PoC, no response - Apr 06, 2026 - GHSA filed after 44 days without acknowledgment Suggested Fix func (s *Server) CompletionsHandler(ctx context.Context, params *mcp.CompleteParams) (*mcp.CompleteResult, error) { if params == nil || params.Ref == nil { return nil, fmt.Errorf("invalid request: missing ref parameter") } // ... rest of handler }

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
high — CVSS 7.5
Published
2026-07-28
Last updated
2026-07-28
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-w4q6-qw23-4rg7

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-47427coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from GitHub Security Advisories