Tier C — Restricted Pending Review
Source: UK AI Open Code Risk & Resilience Governance — 2026-07-27
Risk Scoring
| Dimension |
Score (1–5) |
Notes |
| Exposure amplification |
4 |
MCP server is runtime-facing; CVE in libc6 affects all process memory operations |
| Patchability |
5 |
No upstream Debian fix available yet for CVE-2026-5450 |
| Detectability |
3 |
Memory-corruption exploits are moderately hard to detect |
| Operational fragility |
3 |
Rebuilding images requires coordinated release |
| Ownership confidence |
4 |
Named owners; active monitoring via container-image-scan workflow |
| Overall |
3.8 |
High priority |
Affected Images
Remediation Action (SLA: High — 14 days)
- Monitor [Debian Bookworm security tracker]((securitytracker.debian.org/redacted) for a libc6 patch
- When a fix is published: rebuild and re-publish both images with updated libc6
- Evaluate distroless or minimal base image to reduce libc6 attack surface long-term
- Until patched: ensure MCP server network exposure is restricted to trusted callers
Exception (temporary, expires 2026-09-27)
- Threat hypothesis: Remote code execution via libc6 memory corruption
- Exploit acceleration: Moderate — public CVE, no PoC observed
- Operational weakness: Container rebuild blocked on upstream Debian patch
- Mitigation: Network isolation + weekly Debian tracker monitoring
- Expiry: 2026-09-27 — must be closed or renewed
Human Review Trigger
If CVE-2026-5450 PoC is published or CVSS is elevated to 9.0+, escalate to P0 rebuild immediately.
Related: #48151, #48150 | Governance discussion
Generated by UK AI Operational Resilience · sonnet46 · 83.5 AIC · ⌖ 7.39 AIC · ⊞ 5.3K · ◷
Tier C — Restricted Pending Review
Source: UK AI Open Code Risk & Resilience Governance — 2026-07-27
Risk Scoring
Affected Images
ghcr.io/github/github-mcp-server:v1.7.0— CVE-2026-5450 (Critical), CVE-2026-5928 (High), CVE-2026-5435 (High) in libc6 2.36-9+deb12u14ghcr.io/github/gh-aw-node— similar libc6 issuesRemediation Action (SLA: High — 14 days)
Exception (temporary, expires 2026-09-27)
Human Review Trigger
If CVE-2026-5450 PoC is published or CVSS is elevated to 9.0+, escalate to P0 rebuild immediately.
Related: #48151, #48150 | Governance discussion