github.com/stacklok/toolhive
Go3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/stacklok/toolhivepage 1 of 1
- CVE-2026-54450LOWCVSS 2.9EG 2.9✓ Fixed in 0.29.12026-07-15
ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.29.1, networking.IsPrivateIP in pkg/networking/utilities.go omits the IPv6 NAT64 prefixes 64:ff9b::/96 and 64:ff9b…
- CVE-2026-58196MEDIUMCVSS 4.7EG 4.7✓ Fixed in 0.31.02026-07-15
ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.31.0, remote.Handler.Authenticate in pkg/auth/remote/handler.go invokes discovery.DetectAuthenticationFromServer i…
- CVE-2026-58197HIGHCVSS 8.8EG 8.8✓ Fixed in 0.30.12026-09-18
ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, locally run MCP server containers use the default network permission profi…
Check whether github.com/stacklok/toolhive is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/stacklok/toolhive CVEs against the assets you own.
Start Free Scan →