CVEs we hold for Github
Records whose assigning authority named Github as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-9312Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to internal services via path…GitHub Enterprise Server
CVE-2026-9132Missing authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository contents via…GitHub Enterprise Server
CVE-2026-9106UI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organization runner management via…GitHub Enterprise Server
CVE-2026-8606Server-Side Request Forgery in GitHub Enterprise Server via Advisory Package URL EndpointGitHub Enterprise Server
CVE-2026-8106Reflected HTML injection vulnerability in GitHub Enterprise Server Management Console login page allowed credential…GitHub Enterprise Server
CVE-2026-8034Server-side request forgery vulnerability in GitHub Enterprise Server notebook viewer via URL parser confusionGitHub Enterprise Server
CVE-2026-76851Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed remote code execution via network access…GitHub Enterprise Server
CVE-2026-7541Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via unauthenticated API endpointGitHub Enterprise Server
CVE-2026-6736Authentication bypass vulnerability in GitHub Enterprise Server allowed creation of local user accounts bypassing the…GitHub Enterprise Server
CVE-2026-5921Server-Side Request Forgery in GitHub Enterprise Server allowed extraction of sensitive environment variables via…GitHub Enterprise Server
CVE-2026-5845Improper authorization fallback allows scoped user-to-server token installation escape in GitHub Enterprise ServerGitHub Enterprise Server
CVE-2026-5512Improper authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository names via…GitHub Enterprise Server
CVE-2026-54163secure_headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted inputgithub secure_headers
CVE-2026-48529GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusiongithub-mcp-server
CVE-2026-47427GitHub MCP Server: Nil Pointer Dereference DoS in completion/complete Handlergithub-mcp-server
CVE-2026-45033GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitorgithub copilot-cli
CVE-2026-4296Incorrect Regular Expression vulnerability in GitHub Enterprise Server allowed unauthorized access to user accounts via…GitHub Enterprise Server
CVE-2026-3854Remote code execution via git push option injection in GitHub Enterprise ServerGitHub Enterprise Server
CVE-2026-3582Incorrect Authorization in GitHub Enterprise Server allows access to issue and commit search results without repo scopeGitHub Enterprise Server
CVE-2026-3307Authorization bypass in GitHub Enterprise Server secret scanning push protection allows cross-repository modification…GitHub Enterprise Server
CVE-2026-3306Improper authorization in GitHub Projects allows modification of issue and pull request metadata without repository…GitHub Enterprise Server
CVE-2026-32284Denial of service in github.com/shamaton/msgpackgithub.com/shamaton/msgpack; github.com/shamaton/msgpack/v2…
CVE-2026-29783GitHub Copilot CLI allows for dangerous shell expansion patterns that enable arbitrary command executiongithub copilot-cli
CVE-2026-2266Improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site…GitHub Enterprise Server
CVE-2026-1999Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized merging of…GitHub Enterprise Server
CVE-2026-19118Race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code executionGitHub Enterprise Server
CVE-2026-18730Server-side request forgery vulnerability in GitHub Enterprise Server Manage API leaked a replayable gateway-agent…GitHub Enterprise Server
CVE-2026-17556Path traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance storage via the…GitHub Enterprise Server
CVE-2026-15996Denial of service vulnerability in GitHub Enterprise Server allowed unauthenticated service disruption via deeply…GitHub Enterprise Server
CVE-2026-15783Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository…GitHub Enterprise Server
CVE-2026-15343Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including…GitHub Enterprise Server
CVE-2026-15007Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via deeply nested YAML in…GitHub Enterprise Server
CVE-2026-14340An incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public…GitHub Enterprise Server
CVE-2026-1355Missing Authorization Check in GitHub Enterprise Server Allows Unauthorized Uploads to Repository Migration ExportsGitHub Enterprise Server
CVE-2026-10585Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed arbitrary JavaScript execution via…GitHub Enterprise Server
CVE-2026-0756github-kanban-mcp-server execAsync Command Injection Remote Code Execution Vulnerabilitygithub-kanban-mcp-server
CVE-2026-0573Improper Handling of HTTP Redirects vulnerability was identified in GitHub Enterprise Server that allowed leaking of…GitHub Enterprise Server
CVE-2025-8447Incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed read-only accessGitHub Enterprise Server
CVE-2025-6981Incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized read-only…GitHub Enterprise Server
CVE-2025-68120Unexpected untrusted code execution in github.com/golang/vscode-gogithub.com/golang/vscode-go
CVE-2025-6600GitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Search APIGitHub Enterprise Server
CVE-2025-47909Improper validation of TrustedOrigins allows CSRF attacks in github.com/gorilla/csrfgithub.com/gorilla/csrf
CVE-2025-47908Denial of service via malicious preflight requests in github.com/rs/corsgithub.com/rs/cors
CVE-2025-3509Pre-Receive Hook Remote Code Execution vulnerability was identified in GitHub Enterprise Server that allowing Privilege…GitHub Enterprise Server
CVE-2025-3246Markdown math block sanitization bypass allows privilege escalation and unauthorized workflow triggersGitHub Enterprise Server
CVE-2025-3124Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized access to…GitHub Enterprise Server
CVE-2025-24362CodeQL GitHub Action failed workflow writes GitHub PAT to debug artifactsgithub codeql-action
CVE-2025-23369Improper Verification of Cryptographic Signature in GitHub Enterprise Server Allows Signature Spoofing by Improper…GitHub Enterprise Server
CVE-2025-14046Insufficient HTML Sanitization Allows User-Controlled DOM Elements to Overwrite Server-Initialized Data Islands and…GitHub Enterprise Server
CVE-2025-13744Improper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub Enterprise Server…GitHub Enterprise Server
CVE-2025-11892DOM-based Cross-Site Scripting was identified in GitHub Enterprise Server Issues search allows privilege escalation and…GitHub Enterprise Server
CVE-2025-11578Pre-Receive Hook Path Collision Vulnerability in GitHub Enterprise Server Allowing Privilege EscalationGitHub Enterprise Server
CVE-2024-9487An Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that…GitHub Enterprise Server
CVE-2024-8810Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed GitHub Apps to grant…GitHub Enterprise Server
CVE-2024-6395GitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Deploy KeysGitHub Enterprise Server
CVE-2024-6337Incorrect Authorization allows read access to issues in GitHub Enterprise ServerGitHub Enterprise Server
CVE-2024-6336Security misconfiguration was identified in GitHub Enterprise Server that allowed sensitive data exposureGitHub Enterprise Server
CVE-2024-5817Improper authorization allows read access to issue content in GitHub Enterprise ServerGitHub Enterprise Server
CVE-2024-5816Improper authorization allows persistent access in GitHub Enterprise ServerGitHub Enterprise Server
CVE-2024-5815Cross Site Request Forgery was identified in GitHub Enterprise Server that allowed write in a user owned repositoryGitHub Enterprise Server
CVE-2024-5795Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed resource exhaustionGitHub Enterprise Server
CVE-2024-5566Improper Privilege Management allows for access to unauthorized repository content during migrationGitHub Enterprise Server
CVE-2024-3684Improper Privilege Management was identified in GitHub Enterprise Server that allowed privilege escalation in the…GitHub Enterprise Server
CVE-2024-3646Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the…GitHub Enterprise Server
CVE-2024-3470Repository administrator can bypass organization's ruleset using deploy keysGitHub Enterprise Server
CVE-2024-2748CSRF vulnerability was identified in GitHub Enterprise Server that allowed performing actions on behalf of a userGitHub Enterprise Server
CVE-2024-2469Remote Code Execution in GitHub Enterprise Server Allowed Administrators to gain SSH access to the applianceGitHub Enterprise Server
CVE-2024-2443Improper input validation vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in…GitHub Enterprise Server
CVE-2024-2440Race Condition was identified in GitHub Enterprise Server that allowed maintaining admin permissionsGitHub Enterprise Server
CVE-2024-1908Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed Privilege EscalationGitHub Enterprise Server
CVE-2024-1482Improper Authorization in GitHub Enterprise Server allowed unauthorized workflow executionGitHub Enterprise Server
CVE-2024-1378Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the…GitHub Enterprise Server
CVE-2024-1374Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the…GitHub Enterprise Server
CVE-2024-1372Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the…GitHub Enterprise Server
CVE-2024-1369Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the…GitHub Enterprise Server
CVE-2024-1359Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the…GitHub Enterprise Server
CVE-2024-1355Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the…GitHub Enterprise Server
CVE-2024-1354Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the…GitHub Enterprise Server
CVE-2024-10824Authorization Bypass Vulnerability was Identified in GitHub Enterprise Server that Allowed Unauthorized Internal Users…GitHub Enterprise Server
CVE-2024-1082Path traversal vulnerability in GitHub Enterprise Server that allowed arbitrary file read with a specially crafted…GitHub Enterprise Server
CVE-2024-10007Pre-Receive Hook Path Collision Vulnerability in GitHub Enterprise Server Allowing Privilege EscalationGitHub Enterprise Server
CVE-2024-10001Code Injection Vulnerability in GitHub Enterprise Server Allows Arbitrary Code Execution via Message HandlingGitHub Enterprise Server
CVE-2024-0507Privilege Escalation by Code Injection in the Management Console in GitHub Enterprise ServerGitHub Enterprise Server
CVE-2024-0200Unsafe Reflection in Github Enterprise Server leading to Command InjectionGitHub Enterprise Server
CVE-2023-6847Improper Authentication in GitHub Enterprise Server leading to Authentication Bypass for Public Repository DataGitHub Enterprise Server
CVE-2023-6804Improper Privilege Management allows for arbitrary workflows to be runGitHub Enterprise Server
CVE-2023-51380Incorrect Authorization allows Read Access to Issue Comments in GitHub Enterprise ServerGitHub Enterprise Server
CVE-2023-51379Incorrect Authorization for Issue Comments in GitHub Enterprise ServerGitHub Enterprise Server
CVE-2023-46649Race Condition allows Administrative Access on Organization RepositoriesGitHub Enterprise Server
CVE-2023-46648Insufficient Entropy in GitHub Enterprise Server Management Console Invitation TokenGitHub Enterprise Server
CVE-2023-46647Improper Privilege Management in GitHub Enterprise Server management console leads to privilege escalationGitHub Enterprise Server
CVE-2023-46645Path traversal in GitHub Enterprise Server leading to arbitrary file reading when building a GitHub Pages siteGitHub Enterprise Server
CVE-2023-45292Captcha verification bypass in github.com/mojocn/base64Captchagithub.com/mojocn/base64Captcha
CVE-2023-45286HTTP request body disclosure in github.com/go-resty/resty/v2github.com/go-resty/resty/v2
CVE-2023-29401Improper handling of filenames in Content-Disposition HTTP header in github.com/gin-gonic/gingithub.com/gin-gonic/gin
CVE-2023-23766Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smugglingGitHub Enterprise Server
CVE-2023-23765Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smugglingGitHub Enterprise Server
CVE-2023-23764Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smugglingGitHub Enterprise Server
CVE-2023-23763Information disclosure in GitHub Enterprise Server leading to private repository leakageGitHub Enterprise Server
CVE-2023-23762Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smugglingGitHub Enterprise Server
CVE-2023-23761Improper authentication vulnerability in GitHub Enterprise Server leading to modification of secret gistsGitHub Enterprise Server
CVE-2023-23760Path traversal in GitHub Enterprise Server leading to remote code executionGitHub Enterprise Server
CVE-2023-22486cmark-gfm Quadratic complexity bug in handle_close_bracket may lead to a denial of servicegithub cmark-gfm
CVE-2023-22484Inefficient Quadratic complexity bug in handle_pointy_brace may lead to a denial of servicegithub cmark-gfm
CVE-2023-22381Code injection in GitHub Enterprise Server leading to arbitrary environment variables in GitHub ActionsGitHub Enterprise Server
CVE-2023-22380Path traversal in GitHub Enterprise Server leading to arbitrary file reading when building a GitHub Pages siteGitHub Enterprise Server
CVE-2022-46258Incorrect Authorization in GitHub Enterprise Server leads to Action Workflow modifications without Workflow ScopeGitHub Enterprise Server
CVE-2022-46257Information disclosure in GitHub Enterprise Server leading to unauthorized viewing of private repository namesGitHub Enterprise Server
CVE-2022-46256Path traversal in GitHub Enterprise Server leading to remote code execution in GitHub PagesGitHub Enterprise Server
CVE-2022-46255Improper Limitation of a Pathname to a Restricted Directory in GitHub Enterprise Server leading to RCEGitHub Enterprise Server
CVE-2022-3347Incorrect validation of root DNSSEC public keys in github.com/peterzen/goresolvergithub.com/peterzen/goresolver
CVE-2022-3346Incorrect DNSSEC validation due to unchecked owner names in github.com/peterzen/goresolvergithub.com/peterzen/goresolver
CVE-2022-2584Panic when decoding invalid blocks in github.com/ipld/go-codec-dagpbgithub.com/ipld/go-codec-dagpb
CVE-2022-2583Race condition in github.com/ntbosscher/gobasegithub.com/ntbosscher/gobase/auth/httpauth
CVE-2022-2582Exposure of unencrypted plaintext hash in github.com/aws/aws-sdk-gogithub.com/aws/aws-sdk-go/service/s3/s3crypto
CVE-2022-24724Integer overflow in table parsing extension leads to heap memory corruptiongithub cmark-gfm
CVE-2022-23741Incorrect authorization in GitHub Enterprise Server token generation leading to full admin accessGitHub Enterprise Server
CVE-2022-23740Improper Neutralization of Argument Delimiters in a Command in GitHub Enterprise Server leading to Remote Code ExecutionGitHub Enterprise Server
CVE-2022-23739Incorrect authorization check in GitHub Enterprise Server leading to escalation of privileges in GraphQL API requests…GitHub Enterprise Server
CVE-2022-23738Incomplete cache verification issue in GitHub Enterprise Server leading to exposure of private repo filesGitHub Enterprise Server
CVE-2022-23737Improper Privilege Management in GitHub Enterprise Server leading to page creation and deletionGitHub Enterprise Server
CVE-2022-23734Deserialization of Untrusted Data vulnerability in GitHub Enterprise Server leading to Remote Code ExecutionGitHub Enterprise Server
CVE-2022-23733Stored XSS vulnerability in GitHub Enterprise Server leading to injection of arbitrary attributesGitHub Enterprise Server
CVE-2022-23732Path traversal in GitHub Enterprise Server management console leading to a bypass of CSRF protectionsGitHub Enterprise Server
CVE-2021-4238Insufficient randomness in github.com/Masterminds/goutilsgithub.com/Masterminds/goutils
CVE-2021-41599Improper control flow in GitHub Enterprise Server hosted Pages leads to remote code executionGitHub Enterprise Server
CVE-2021-41598UI misrepresentation of granted permissions in GitHub Enterprise Server leading to unauthorized access to userGitHub Enterprise Server
CVE-2021-32638CodeQL runner: Command-line options that make GitHub access tokens visible to other processes are now deprecatedgithub codeql-action
CVE-2021-22870Path traversal in GitHub Enterprise Server hosted Pages leads to unauthorized file read accessGitHub Enterprise Server
CVE-2021-22869Improper access control in GitHub Enterprise Server allows self-hosted runners to execute outside their control groupGitHub Enterprise Server
CVE-2021-22868Unsafe configuration options in GitHub Pages leading to path traversal on GitHub Enterprise ServerGitHub Enterprise Server
CVE-2021-22867Unsafe configuration options in GitHub Pages leading to path traversal on GitHub Enterprise ServerGitHub Enterprise Server
CVE-2021-22866UI misrepresentation of granted permissions in GitHub Enterprise Server leading to unauthorized access to user resourcesGitHub Enterprise Server
CVE-2021-22865Improper access control in GitHub Enterprise Server leading to unauthorized read access to private repository metadataGitHub Enterprise Server
CVE-2021-22864Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise ServerGitHub Enterprise Server
200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.