OPENSUSE-SU-2026:21771-1
Advisory lineage Upstream: 2 Downstream: 0
Upstream
Published: 06 Sept 2026, 16:48
Last modified:09 Sept 2026, 18:23
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
06 Sept 2026, 16:48
Published
Vulnerability first disclosed
09 Sept 2026, 18:23
Last Modified
Vulnerability information updated
Description
Security update for mcphost This update for mcphost fixes the following issues: - CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276612). - CVE-2026-81092: github.com/mark3labs/mcp-go/server: requests accepted in HTTP transports without Host header checks can lead to tool usage and resource exposure in target server (bsc#1278013). Changes for mcphost: - Update github.com/mark3labs/mcp-go/server to v0.56.0. - Update go.opentelemetry.io/otel to 1.44.0.
Affected Systems
- opensuse•mcphost&distro=openSUSE Leap 16.0
< 0.34.0-160000.4.1