openSUSE-SU-2026:21771-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21771-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:21771-1
Upstream
CVE (2)
Related
Published
2026-09-06T16:48:02Z
Modified
2026-09-09T18:23:14Z
Summary
Security update for mcphost
Details

This update for mcphost fixes the following issues:

  • CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276612).
  • CVE-2026-81092: github.com/mark3labs/mcp-go/server: requests accepted in HTTP transports without Host header checks can lead to tool usage and resource exposure in target server (bsc#1278013).

Changes for mcphost:

  • Update github.com/mark3labs/mcp-go/server to v0.56.0.
  • Update go.opentelemetry.io/otel to 1.44.0.
References

Affected packages

openSUSE:Leap 16.0 / mcphost

Package

Name
mcphost
Purl
pkg:rpm/opensuse/mcphost&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.34.0-160000.4.1

Ecosystem specific

{
    "binaries":  [
        {
            "mcphost":  "0.34.0-160000.4.1",
            "mcphost-bash-completion":  "0.34.0-160000.4.1",
            "mcphost-fish-completion":  "0.34.0-160000.4.1",
            "mcphost-zsh-completion":  "0.34.0-160000.4.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21771-1.json"