openSUSE-SU-2026:21771-1
Dashboard / Vulnerabilities / openSUSE-SU-2026:21771-1
openSUSE-SU-2026:21771-1
Summary: Security update for mcphost
Details: This update for mcphost fixes the following issues: - CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276612). - CVE-2026-81092: github.com/mark3labs/mcp-go/server: requests accepted in HTTP transports without Host header checks can lead to tool usage and resource exposure in target server (bsc#1278013). Changes for mcphost: - Update github.com/mark3labs/mcp-go/server to v0.56.0. - Update go.opentelemetry.io/otel to 1.44.0.
References: , https://bugzilla.suse.com/1276612, https://bugzilla.suse.com/1278013, https://www.suse.com/security/cve/CVE-2026-41178, https://www.suse.com/security/cve/CVE-2026-81092
Affected packages
Package
Name: mcphost
Purl: pkg:rpm/opensuse/mcphost&distro=openSUSE%20Leap%2016.0
Affected ranges
Type: ECOSYSTEM
Events:
