{"id":"GHSA-w4q6-qw23-4rg7","summary":"GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler","details":"### Summary\n\nA nil pointer dereference vulnerability in the GitHub MCP Server causes it to crash when receiving a malformed `completion/complete` request with missing or empty parameters. This allows any unauthenticated client to cause a complete denial of service.\n\n### Details\n\nThe `CompletionsHandler` function in `pkg/github/server.go:198` accesses `params.Ref` without checking if it's nil first. When a client sends a `completion/complete` request with a missing `ref` field, the handler dereferences nil and the Go runtime panics.\n\nThe crash occurs before any authentication or token validation, so even requests with fake tokens can trigger it.\n\n### PoC\n\nAfter completing the MCP initialization handshake, send either:\n\n**Empty params:**\n\n    {\"jsonrpc\":\"2.0\",\"id\":2,\"method\":\"completion/complete\",\"params\":{}}\n\n**Missing ref field:**\n\n    {\"jsonrpc\":\"2.0\",\"id\":2,\"method\":\"completion/complete\",\"params\":{\"argument\":{\"name\":\"x\",\"value\":\"y\"}}}\n\n**Result:**\n\n    panic: runtime error: invalid memory address or nil pointer dereference\n    goroutine 42 [running]:\n    github.com/github/github-mcp-server/pkg/github.NewMCPServer.CompletionsHandler.func1(...)\n        pkg/github/server.go:198 +0x24\n\n### Impact\n\nAny unauthenticated client that can send JSON-RPC messages to the server can crash it immediately. This is a complete denial of service - the panic is unrecoverable and kills the process.\n\nAutomated fuzzing with mcpsec found 108 crashes out of 925 test cases (11.7% crash rate).\n\n### Timeline\n\n- **Feb 21, 2026** - Initial report sent to opensource-security@github.com\n- **Mar 03, 2026** - Follow-up email sent, no response\n- **Mar 21, 2026** - Re-verified on v0.33.0, sent detailed report with PoC, no response\n- **Apr 06, 2026** - GHSA filed after 44 days without acknowledgment\n\n### Suggested Fix\n\n    func (s *Server) CompletionsHandler(ctx context.Context, params *mcp.CompleteParams) (*mcp.CompleteResult, error) {\n        if params == nil || params.Ref == nil {\n            return nil, fmt.Errorf(\"invalid request: missing ref parameter\")\n        }\n        // ... rest of handler\n    }","aliases":["CVE-2026-47427","GO-2026-6118"],"modified":"2026-08-18T15:10:53.871848995Z","published":"2026-07-28T14:35:10Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-07-28T14:35:10Z","nvd_published_at":null,"cwe_ids":["CWE-476"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/github/github-mcp-server/security/advisories/GHSA-w4q6-qw23-4rg7"},{"type":"WEB","url":"https://github.com/github/github-mcp-server/pull/2502"},{"type":"WEB","url":"https://github.com/github/github-mcp-server/commit/c88d2ecdd3bb07f7bdd75296e3ee676febf14f58"},{"type":"PACKAGE","url":"https://github.com/github/github-mcp-server"},{"type":"WEB","url":"https://github.com/github/github-mcp-server/releases/tag/v1.1.0"}],"affected":[{"package":{"name":"github.com/github/github-mcp-server","ecosystem":"Go","purl":"pkg:golang/github.com/github/github-mcp-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.1.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-w4q6-qw23-4rg7/GHSA-w4q6-qw23-4rg7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}