CVE-2026-47427: GitHub MCP Server: Nil Pointer Dereference DoS in completion/complete Handler

Published Jul 28, 2026
·
Updated

Summary

A nil pointer dereference vulnerability in the GitHub MCP Server causes it to crash when receiving a malformed completion/complete request with missing or empty parameters. This allows any unauthenticated client to cause a complete denial of service.

Details

The CompletionsHandler function in pkg/github/server.go:198 accesses params.Ref without checking if it's nil first. When a client sends a completion/complete request with a missing ref field, the handler dereferences nil and the Go runtime panics.

The crash occurs before any authentication or token validation, so even requests with fake tokens can trigger it.

PoC

After completing the MCP initialization handshake, send either:

Empty params:

{"jsonrpc":"2.0","id":2,"method":"completion/complete","params":{}}

Missing ref field:

{"jsonrpc":"2.0","id":2,"method":"completion/complete","params":{"argument":{"name":"x","value":"y"}}}

Result:

panic: runtime error: invalid memory address or nil pointer dereference goroutine 42 [running]: github.com/github/github-mcp-server/pkg/github.NewMCPServer.CompletionsHandler.func1(...) pkg/github/server.go:198 +0x24

Impact

Any unauthenticated client that can send JSON-RPC messages to the server can crash it immediately. This is a complete denial of service - the panic is unrecoverable and kills the process.

Automated fuzzing with mcpsec found 108 crashes out of 925 test cases (11.7% crash rate).

Timeline

- Feb 21, 2026 - Initial report sent to opensource-security@github.com - Mar 03, 2026 - Follow-up email sent, no response - Mar 21, 2026 - Re-verified on v0.33.0, sent detailed report with PoC, no response - Apr 06, 2026 - GHSA filed after 44 days without acknowledgment

Suggested Fix

func (s Server) CompletionsHandler(ctx context.Context, params mcp.CompleteParams) (mcp.CompleteResult, error) { if params == nil || params.Ref == nil { return nil, fmt.Errorf("invalid request: missing ref parameter") } // ... rest of handler }

Other sources

GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref without first checking whether it is nil, so a completion/complete request with a missing or empty ref field triggers a nil pointer dereference and a Go runtime panic; because the crash occurs before any authentication or token validation, any unauthenticated client able to send JSON-RPC messages can crash the server, resulting in a complete denial of service. This issue is fixed in version 1.1.0.

MITRE

Affected Software

2 affected componentsFixes available
go/github.com/github/github-mcp-server<1.1.0
1.1.0
GitHub MCP Server<1.1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/github/github-mcp-server to a version that resolves this vulnerability.

    Fixed in 1.1.0
  2. Upgrade

    Upgrade GitHub MCP Server to a version that resolves this vulnerability.

    Fixed in 1.1.0

Event History

Jul 28, 2026
Advisory Published
via GitHub·02:35 PM
Data Sourced
via GitHub·02:35 PM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·03:32 PM
Data Sourced
via MITRE·03:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:18 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-47427?

The severity of CVE-2026-47427 is rated as high, with a score of 7.5.

2

How does CVE-2026-47427 affect the GitHub MCP Server?

CVE-2026-47427 allows unauthenticated clients to crash the GitHub MCP Server, resulting in a denial of service.

3

What is the nature of the vulnerability in CVE-2026-47427?

CVE-2026-47427 is a nil pointer dereference vulnerability that occurs when handling malformed 'completion/complete' requests.

4

Who can exploit CVE-2026-47427?

CVE-2026-47427 can be exploited by any unauthenticated client.

5

How can I fix CVE-2026-47427?

To mitigate CVE-2026-47427, you should update to the latest version of the GitHub MCP Server that addresses this vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203