SUSE-SU-2026:23496-1
Dashboard / Vulnerabilities / SUSE-SU-2026:23496-1
SUSE-SU-2026:23496-1
Summary: Security update for mcphost
Details: This update for mcphost fixes the following issues: - CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276612). - CVE-2026-81092: github.com/mark3labs/mcp-go/server: requests accepted in HTTP transports without Host header checks can lead to tool usage and resource exposure in target server (bsc#1278013). Changes for mcphost: - Update github.com/mark3labs/mcp-go/server to v0.56.0. - Update go.opentelemetry.io/otel to 1.44.0.
References: https://www.suse.com/support/update/announcement/2026/suse-su-202623496-1/, https://bugzilla.suse.com/1276612, https://bugzilla.suse.com/1278013, https://www.suse.com/security/cve/CVE-2026-41178, https://www.suse.com/security/cve/CVE-2026-81092
Affected packages
Package
Name: mcphost
Purl: pkg:rpm/suse/mcphost&distro=SUSE%20Linux%20Micro%206.2
Affected ranges
Type: ECOSYSTEM
Events:
