github
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting github.
- CVE-2026-75101Authorization bypass vulnerability in GitHub Enterprise Server allowed reading of private pull request diffs and patches via repository name collision
- CVE-2026-77912Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed HTML attribute injection via the Markdown rendering pipeline
- CVE-2026-77987GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgery
- CVE-2026-76851Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed remote code execution via network access from pre-receive hooks to internal services8.8
- CVE-2026-19118Race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution7.5
- CVE-2026-18730Server-side request forgery vulnerability in GitHub Enterprise Server Manage API leaked a replayable gateway-agent bearer token7.4
- CVE-2026-18428SQL Query Validation Bypass in OpenSearch Direct Query8.8
- CVE-2026-18952Missing Input Validation in Threat Intel Feed Parser in OpenSearch Security Analytics Plugin8.1
- CVE-2026-19311Missing Authorization in Execute Monitor API in OpenSearch Alerting Plugin8.1
- CVE-2026-15996Denial of service vulnerability in GitHub Enterprise Server allowed unauthenticated service disruption via deeply nested request parameters7.5
- CVE-2026-17556Path traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance storage via the X-GitHub-Request-Id header9.1
- CVE-2026-47427GitHub MCP Server: Nil Pointer Dereference DoS in completion/complete Handler7.5
- CVE-2026-54163secure_headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input4.7
- CVE-2026-15783Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suites
- CVE-2026-15343Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot dependency-file paths