github.com/docker/mcp-gateway
Go2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/docker/mcp-gatewaypage 1 of 1
- CVE-2025-64443CRITICALCVSS 9.6EG 9.6✓ Fixed in 0.28.02025-12-03
MCP Gateway allows easy and secure running and deployment of MCP servers. In versions 0.27.0 and earlier, when MCP Gateway runs in sse or streaming transport mode, it is vulnerable to DNS rebinding. An attacker who can get a victim to visi…
- CVE-2026-55887HIGHCVSS 0.0EG 0.0✓ Fixed in 0.42.22026-06-18
Docker MCP Gateway: Argument injection via OCI image label YAML ## Summary A maliciously crafted OCI image label can inject arbitrary arguments into the `docker run` command line constructed by the MCP Gateway. An attacker who controls a…
Check whether github.com/docker/mcp-gateway is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/docker/mcp-gateway CVEs against the assets you own.
Start Free Scan →