CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-47427

highCVSS 7.5covered by 2 sourcesfirst seen 2026-07-28
Summary A nil pointer dereference vulnerability in the GitHub MCP Server causes it to crash when receiving a malformed completion/complete request with missing or empty parameters. This allows any unauthenticated client to cause a complete denial of service. Details The CompletionsHandler function in pkg/github/server.go:198 accesses params.Ref without checking if it's nil first. When a client sends a completion/complete request with a missing ref field, the handler dereferences nil and the Go runtime panics. The crash occurs before any authentication or token validation, so even requests with fake tokens can trigger it. PoC After completing the MCP initialization handshake, send either: Empty params: {"jsonrpc":"2.0","id":2,"method":"completion/complete","params":{}} Missing ref field: {"jsonrpc":"2.0","id":2,"method":"completion/complete","params":{"argument":{"name":"x","value":"y"}}} Result: panic: runtime error: invalid memory address or nil pointer dereference goroutine 42 [running]: github.com/github/github-mcp-server/pkg/github.NewMCPServer.CompletionsHandler.func1(...) pkg/github/server.go:198 +0x24 Impact Any unauthenticated client that can send JSON-RPC messages to the server can crash it immediately. This is a complete denial of service - the panic is unrecoverable and kills the process. Automated fuzzing with mcpsec found 108 crashes out of 925 test cases (11.7% crash rate). Timeline - Feb 21, 2026 - Initial report sent to opensource-security@github.com - Mar 03, 2026 - Follow-up email sent, no response - Mar 21, 2026 - Re-verified on v0.33.0, sent detailed report with PoC, no response - Apr 06, 2026 - GHSA filed after 44 days without acknowledgment Suggested Fix func (s *Server) CompletionsHandler(ctx context.Context, params *mcp.CompleteParams) (*mcp.CompleteResult, error) { if params == nil || params.Ref == nil { return nil, fmt.Errorf("invalid request: missing ref parameter") } // ... rest of handler }

⚡ Watch CVE-2026-47427

Get an email if CVE-2026-47427 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-47427

CVE.org record

Embed the live status

CVE-2026-47427 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-47427 status](https://www.csirts.com/badge/CVE-2026-47427)](https://www.csirts.com/cve/CVE-2026-47427)