CVE-2026-47427: GitHub MCP Server: Nil Pointer Dereference DoS in completion/complete Handler
Summary
A nil pointer dereference vulnerability in the GitHub MCP Server causes it to crash when receiving a malformed completion/complete request with missing or empty parameters. This allows any unauthenticated client to cause a complete denial of service.
Details
The CompletionsHandler function in pkg/github/server.go:198 accesses params.Ref without checking if it's nil first. When a client sends a completion/complete request with a missing ref field, the handler dereferences nil and the Go runtime panics.
The crash occurs before any authentication or token validation, so even requests with fake tokens can trigger it.
PoC
After completing the MCP initialization handshake, send either:
Empty params:
{"jsonrpc":"2.0","id":2,"method":"completion/complete","params":{}}
Missing ref field:
{"jsonrpc":"2.0","id":2,"method":"completion/complete","params":{"argument":{"name":"x","value":"y"}}}
Result:
panic: runtime error: invalid memory address or nil pointer dereference goroutine 42 [running]: github.com/github/github-mcp-server/pkg/github.NewMCPServer.CompletionsHandler.func1(...) pkg/github/server.go:198 +0x24
Impact
Any unauthenticated client that can send JSON-RPC messages to the server can crash it immediately. This is a complete denial of service - the panic is unrecoverable and kills the process.
Automated fuzzing with mcpsec found 108 crashes out of 925 test cases (11.7% crash rate).
Timeline
- Feb 21, 2026 - Initial report sent to opensource-security@github.com - Mar 03, 2026 - Follow-up email sent, no response - Mar 21, 2026 - Re-verified on v0.33.0, sent detailed report with PoC, no response - Apr 06, 2026 - GHSA filed after 44 days without acknowledgment
Suggested Fix
func (s Server) CompletionsHandler(ctx context.Context, params mcp.CompleteParams) (mcp.CompleteResult, error) { if params == nil || params.Ref == nil { return nil, fmt.Errorf("invalid request: missing ref parameter") } // ... rest of handler }
Other sources
GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref without first checking whether it is nil, so a completion/complete request with a missing or empty ref field triggers a nil pointer dereference and a Go runtime panic; because the crash occurs before any authentication or token validation, any unauthenticated client able to send JSON-RPC messages can crash the server, resulting in a complete denial of service. This issue is fixed in version 1.1.0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/github/github-mcp-serverto a version that resolves this vulnerability.Fixed in 1.1.0 - Upgrade
Upgrade
GitHub MCP Serverto a version that resolves this vulnerability.Fixed in 1.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47427?
The severity of CVE-2026-47427 is rated as high, with a score of 7.5.
How does CVE-2026-47427 affect the GitHub MCP Server?
CVE-2026-47427 allows unauthenticated clients to crash the GitHub MCP Server, resulting in a denial of service.
What is the nature of the vulnerability in CVE-2026-47427?
CVE-2026-47427 is a nil pointer dereference vulnerability that occurs when handling malformed 'completion/complete' requests.
Who can exploit CVE-2026-47427?
CVE-2026-47427 can be exploited by any unauthenticated client.
How can I fix CVE-2026-47427?
To mitigate CVE-2026-47427, you should update to the latest version of the GitHub MCP Server that addresses this vulnerability.