OPENSUSE-SU-2026:21771-1

Advisory lineage Upstream: 2 Downstream: 0
Published: 06 Sept 2026, 16:48
Last modified:09 Sept 2026, 18:23

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

06 Sept 2026, 16:48
Published
Vulnerability first disclosed
09 Sept 2026, 18:23
Last Modified
Vulnerability information updated

Description

Security update for mcphost This update for mcphost fixes the following issues: - CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276612). - CVE-2026-81092: github.com/mark3labs/mcp-go/server: requests accepted in HTTP transports without Host header checks can lead to tool usage and resource exposure in target server (bsc#1278013). Changes for mcphost: - Update github.com/mark3labs/mcp-go/server to v0.56.0. - Update go.opentelemetry.io/otel to 1.44.0.

Affected Systems

  • opensusemcphost&distro=openSUSE Leap 16.0

    < 0.34.0-160000.4.1

References (4)