MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2026-5273" }
"https://vuln.go.dev/ID/GO-2026-5273.json"