github
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting github.
- CVE-2026-47427GitHub MCP Server: Nil Pointer Dereference DoS in completion/complete Handler7.5
- CVE-2026-54163secure_headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input4.7
- CVE-2026-14340An incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositories5.0
- CVE-2026-10585Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed arbitrary JavaScript execution via crafted Discussion titles in the Q&A category5.4
- CVE-2026-9132Missing authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository contents via the Copilot pull request diff summary endpoint6.5
- CVE-2026-9106UI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organization runner management via undisclosed OAuth scope on consent screen5.5
- CVE-2026-48529GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion6.0
- CVE-2026-48501GitHub CLI tokens leak via `gh attestation` commands7.4
- CVE-2026-9312Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to internal services via path traversal in upload endpoint8.2
- CVE-2026-8606Server-Side Request Forgery in GitHub Enterprise Server via Advisory Package URL Endpoint5.9
- CVE-2026-45803gh: GitHub Actions log output in `gh run view` allows terminal escape sequence injection3.5
- CVE-2026-45033GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitor7.8
- CVE-2026-8106Reflected HTML injection vulnerability in GitHub Enterprise Server Management Console login page allowed credential theft6.1
- CVE-2026-8034Server-side request forgery vulnerability in GitHub Enterprise Server notebook viewer via URL parser confusion9.8
- CVE-2026-7541Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via unauthenticated API endpoint7.5