Skip to content

馃毃 Security: Critical or high vulnerabilities in adb-mysql-mcp-server container聽#1040

Description

@github-actions

馃毃 Security Scan Alert

A periodic security scan found fixable critical or high severity vulnerabilities in the container image. Findings at this level also block publishing in the build workflow.

  • Image: ghcr.io/stacklok/dockyard/uvx/adb-mysql-mcp-server:2.0.0
  • Critical vulnerabilities: 1
  • High vulnerabilities: 7

Details

See the Security tab for full details.

Critical Vulnerabilities

  • GHSA-ffc3-869f-jxw9 in pyjwt@2.13.0: PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard

High Vulnerabilities

  • GHSA-vxq7-64xx-v4gw in urllib3@2.7.0: urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory
  • GHSA-8988-9cw3-xx77 in urllib3@2.7.0: urllib3: HTTPS proxy TLS configuration may be ignored or overridden
  • GHSA-r6x4-923q-g947 in pyjwt@2.13.0: PyJWT BOM Bypass
  • GHSA-w2cx-738m-mc7w in pyjwt@2.13.0: PyJWT accepts public JWK containers as HMAC secrets
  • GHSA-9j54-fg26-wv3r in pyjwt@2.13.0: PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation

... and 2 more. See Security tab for complete list.


Automated security scan from periodic-security-scan workflow

Activity

  1. cc-bb-aa commented on Oct 5, 2026

    @cc-bb-aa

    Patching the container image is the right fix. In the meantime, wrapping the MCP server with a runtime gate gives you a deny by default layer and an audit trail of every tool call. That way a vulnerable image alone cannot exfiltrate or modify things outside an allowlist. Happy to share the config pattern if it helps: https://shield-agent.com/docs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions