CVE-2026-76851Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed remote code execution via network access from pre-receive hooks to internal services Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 09/01/2026 Severity High CVE-2026-19118Race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 09/01/2026 Severity High CVE-2026-18730Server-side request forgery vulnerability in GitHub Enterprise Server Manage API leaked a replayable gateway-agent bearer token Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 09/01/2026 Severity High CVE-2026-18428SQL Query Validation Bypass in OpenSearch Direct Query Exploitation status Not known exploited Fix YesAffected product O OpenSearch Published 08/13/2026 Severity High CVE-2026-18952Missing Input Validation in Threat Intel Feed Parser in OpenSearch Security Analytics Plugin Exploitation status Not known exploited Fix YesAffected product O OpenSearch Published 08/12/2026 Severity High CVE-2026-19311Missing Authorization in Execute Monitor API in OpenSearch Alerting Plugin Exploitation status Not known exploited Fix YesAffected product O OpenSearch Published 08/12/2026 Severity High CVE-2026-15996Denial of service vulnerability in GitHub Enterprise Server allowed unauthenticated service disruption via deeply nested request parameters Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 08/05/2026 Severity Medium CVE-2026-17556Path traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance storage via the X-GitHub-Request-Id header Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 08/05/2026 Severity High CVE-2026-47427GitHub MCP Server: Nil Pointer Dereference DoS in completion/complete Handler Exploitation status Public exploit Fix YesAffected product G github-mcp-server Published 07/28/2026 Severity High CVE-2026-54163secure_headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input Exploitation status Public exploit Fix YesAffected product S secure_headers Published 07/17/2026 Severity Medium CVE-2026-15783Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suites Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 07/17/2026 Severity Medium CVE-2026-15343Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot dependency-file paths Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 07/17/2026 Severity High CVE-2026-15007Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via deeply nested YAML in release notes configuration Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 07/17/2026 Severity Medium CVE-2026-14340An incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositories Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 07/01/2026 Severity Medium CVE-2026-10585Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed arbitrary JavaScript execution via crafted Discussion titles in the Q&A category Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 06/30/2026 Severity Medium CVE-2026-9132Missing authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository contents via the Copilot pull request diff summary endpoint Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 06/30/2026 Severity Medium CVE-2026-9106UI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organization runner management via undisclosed OAuth scope on consent screen Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 06/30/2026 Severity Medium CVE-2026-48529GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion Exploitation status Public exploit Fix YesAffected product G github-mcp-server Published 06/26/2026 Severity Medium CVE-2026-48501GitHub CLI tokens leak via `gh attestation` commands Exploitation status Not known exploited Fix YesAffected product C cli Published 05/29/2026 Severity High CVE-2026-9312Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to internal services via path traversal in upload endpoint Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 05/27/2026 Severity Critical CVE-2026-8606Server-Side Request Forgery in GitHub Enterprise Server via Advisory Package URL Endpoint Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 05/26/2026 Severity High CVE-2026-45803gh: GitHub Actions log output in `gh run view` allows terminal escape sequence injection Exploitation status Public exploit Fix YesAffected product C cli Published 05/15/2026 Severity Low CVE-2026-45033GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitor Exploitation status Public exploit Fix YesAffected product C copilot-cli Published 05/13/2026 Severity High CVE-2026-8106Reflected HTML injection vulnerability in GitHub Enterprise Server Management Console login page allowed credential theft Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 05/07/2026 Severity Medium CVE-2026-8034Server-side request forgery vulnerability in GitHub Enterprise Server notebook viewer via URL parser confusion Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 05/07/2026 Severity High CVE-2026-7541Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via unauthenticated API endpoint Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 05/07/2026 Severity Medium CVE-2026-6736Authentication bypass vulnerability in GitHub Enterprise Server allowed creation of local user accounts bypassing the configured external identity provider Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 05/07/2026 Severity Medium CVE-2026-5845Improper authorization fallback allows scoped user-to-server token installation escape in GitHub Enterprise Server Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 04/21/2026 Severity High CVE-2026-3307Authorization bypass in GitHub Enterprise Server secret scanning push protection allows cross-repository modification of delegated bypass reviewers Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 04/21/2026 Severity Medium CVE-2026-5512Improper authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository names via mobile upload policy API Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 04/21/2026 Severity Medium CVE-2026-4296Incorrect Regular Expression vulnerability in GitHub Enterprise Server allowed unauthorized access to user accounts via OAuth callback URL validation bypass Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 04/21/2026 Severity High CVE-2026-4821Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 04/21/2026 Severity Unknown CVE-2026-5921Server-Side Request Forgery in GitHub Enterprise Server allowed extraction of sensitive environment variables via timing side-channel attack Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 04/21/2026 Severity High CVE-2026-3582Incorrect Authorization in GitHub Enterprise Server allows access to issue and commit search results without repo scope Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 03/10/2026 Severity Medium CVE-2026-2266Improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site scripting via task list content and enabled arbitrary HTML injection Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 03/10/2026 Severity High CVE-2026-3306Improper authorization in GitHub Projects allows modification of issue and pull request metadata without repository write access Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 03/10/2026 Severity Medium CVE-2026-3854Remote code execution via git push option injection in GitHub Enterprise Server Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 03/10/2026 Severity High CVE-2026-29783GitHub Copilot CLI allows for dangerous shell expansion patterns that enable arbitrary command execution Exploitation status Not known exploited Fix YesAffected product C copilot-cli Published 03/06/2026 Severity High CVE-2018-25188Webiness Inventory 2.3 SQL Injection via WsModelGrid.php Exploitation status Public exploit Fix Not confirmed Affected product W Webiness Inventory Published 03/06/2026 Severity High CVE-2026-1999Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized merging of pull requests Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 02/18/2026 Severity High CVE-2026-1355Missing Authorization Check in GitHub Enterprise Server Allows Unauthorized Uploads to Repository Migration Exports Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 02/18/2026 Severity Medium CVE-2026-0573Improper Handling of HTTP Redirects vulnerability was identified in GitHub Enterprise Server that allowed leaking of authorization token and enabled remote code execution Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 02/18/2026 Severity High CVE-2021-47832Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 01/16/2026 Severity Unknown CVE-2025-13744Improper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub Enterprise Server that allowed rendering of malicious HTML Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 01/06/2026 Severity High CVE-2025-14046Insufficient HTML Sanitization Allows User-Controlled DOM Elements to Overwrite Server-Initialized Data Islands and Trigger Unintended Server-Side POST Requests Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 12/11/2025 Severity High CVE-2025-11578Pre-Receive Hook Path Collision Vulnerability in GitHub Enterprise Server Allowing Privilege Escalation Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 11/10/2025 Severity High CVE-2025-11892DOM-based Cross-Site Scripting was identified in GitHub Enterprise Server Issues search allows privilege escalation and unauthorized workflow triggers Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 11/10/2025 Severity High CVE-2025-8447Incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed read-only access Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 08/26/2025 Severity High CVE-2025-6981Incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized read-only access Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 07/15/2025 Severity Medium CVE-2025-6600GitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Search API Exploitation status Not known exploited Fix YesAffected product G GitHub Enterprise Server Published 07/01/2025 Severity Medium CVE-2025-3246Markdown math block sanitization bypass allows privilege escalation and unauthorized workflow triggers Exploitation status Not known exploited Fix YesAffected product G GitHub Enterprise Server Published 04/17/2025 Severity High CVE-2025-3509Pre-Receive Hook Remote Code Execution vulnerability was identified in GitHub Enterprise Server that allowing Privilege Escalation Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 04/17/2025 Severity High CVE-2025-3124Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized access to private repository names Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 04/17/2025 Severity Medium CVE-2024-10001Code Injection Vulnerability in GitHub Enterprise Server Allows Arbitrary Code Execution via Message Handling Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 01/29/2025 Severity High CVE-2025-24362CodeQL GitHub Action failed workflow writes GitHub PAT to debug artifacts Exploitation status Not known exploited Fix YesAffected product C codeql-action Published 01/24/2025 Severity High CVE-2025-23369Improper Verification of Cryptographic Signature in GitHub Enterprise Server Allows Signature Spoofing by Improper Validation Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 01/21/2025 Severity High CVE-2024-52308Connecting to a malicious Codespaces via GH CLI could allow command execution on the user's computer Exploitation status Not known exploited Fix YesAffected product C cli Published 11/14/2024 Severity High CVE-2024-8810Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed GitHub Apps to grant themselves write access Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 11/07/2024 Severity High CVE-2024-10824Authorization Bypass Vulnerability was Identified in GitHub Enterprise Server that Allowed Unauthorized Internal Users to Access Secret Scanning Alert Data Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 11/07/2024 Severity Medium CVE-2024-10007Pre-Receive Hook Path Collision Vulnerability in GitHub Enterprise Server Allowing Privilege Escalation Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 11/07/2024 Severity High CVE-2024-9539Exploitation status Not known exploited Fix YesAffected product G GitHub Enterprise Server Published 10/11/2024 Severity Medium CVE-2024-9487An Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed when the encrypted assertions feature was enabled Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 10/10/2024 Severity Critical CVE-2024-8263Exploitation status Not known exploited Fix YesAffected product G GitHub Enterprise Server Published 09/23/2024 Severity Medium CVE-2024-8770Exploitation status Not known exploited Fix YesAffected product G GitHub Enterprise Server Published 09/23/2024 Severity Medium CVE-2024-42471Arbitrary File Write via artifact extraction in actions/artifact Exploitation status Not known exploited Fix Not confirmed Affected product T toolkit Published 09/02/2024 Severity High CVE-2024-6800Exploitation status Not known exploited Fix YesAffected product G GitHub Enterprise Server Published 08/20/2024 Severity Critical CVE-2024-6337Incorrect Authorization allows read access to issues in GitHub Enterprise Server Exploitation status Not known exploited Fix YesAffected product G GitHub Enterprise Server Published 08/20/2024 Severity Medium CVE-2024-7711Exploitation status Not known exploited Fix YesAffected product G GitHub Enterprise Server Published 08/20/2024 Severity Medium CVE-2024-6395GitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Deploy Keys Exploitation status Not known exploited Fix YesAffected product G GitHub Enterprise Server Published 07/16/2024 Severity Medium CVE-2024-6336Security misconfiguration was identified in GitHub Enterprise Server that allowed sensitive data exposure Exploitation status Not known exploited Fix YesAffected product G GitHub Enterprise Server Published 07/16/2024 Severity Medium CVE-2024-5817Improper authorization allows read access to issue content in GitHub Enterprise Server Exploitation status Not known exploited Fix YesAffected product G GitHub Enterprise Server Published 07/16/2024 Severity Medium CVE-2024-5816Improper authorization allows persistent access in GitHub Enterprise Server Exploitation status Not known exploited Fix YesAffected product G GitHub Enterprise Server Published 07/16/2024 Severity Medium CVE-2024-5815Cross Site Request Forgery was identified in GitHub Enterprise Server that allowed write in a user owned repository Exploitation status Not known exploited Fix YesAffected product G GitHub Enterprise Server Published 07/16/2024 Severity Medium CVE-2024-5795Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed resource exhaustion Exploitation status Not known exploited Fix YesAffected product G GitHub Enterprise Server Published 07/16/2024 Severity High CVE-2024-5566Improper Privilege Management allows for access to unauthorized repository content during migration Exploitation status Not known exploited Fix YesAffected product G GitHub Enterprise Server Published 07/16/2024 Severity Medium CVE-2024-5746Exploitation status Not known exploited Fix YesAffected product G GitHub Enterprise Server Published 06/20/2024 Severity High CVE-2024-4985Exploitation status Public exploit Fix YesAffected product E Enterprise Server Published 05/20/2024 Severity Critical CVE-2024-2440Race Condition was identified in GitHub Enterprise Server that allowed maintaining admin permissions Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 04/19/2024 Severity Medium CVE-2024-3684Improper Privilege Management was identified in GitHub Enterprise Server that allowed privilege escalation in the Management Console Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 04/19/2024 Severity High CVE-2024-3646Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Management Console Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 04/19/2024 Severity High CVE-2024-3470Repository administrator can bypass organization's ruleset using deploy keys Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 04/19/2024 Severity Medium CVE-2024-2748CSRF vulnerability was identified in GitHub Enterprise Server that allowed performing actions on behalf of a user Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 03/20/2024 Severity Medium CVE-2024-2443Improper input validation vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Management Console Exploitation status Not known exploited Fix YesAffected product G GitHub Enterprise Server Published 03/20/2024 Severity Critical CVE-2024-2469Remote Code Execution in GitHub Enterprise Server Allowed Administrators to gain SSH access to the appliance Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 03/20/2024 Severity High CVE-2024-1908Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed Privilege Escalation Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 02/29/2024 Severity Medium CVE-2024-25129Limited data exfiltration in CodeQL CLI Exploitation status Not known exploited Fix YesAffected product C codeql-cli-binaries Published 02/22/2024 Severity Low CVE-2024-1482Improper Authorization in GitHub Enterprise Server allowed unauthorized workflow execution Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 02/14/2024 Severity High CVE-2024-1378Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 02/13/2024 Severity Critical CVE-2024-1374Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 02/13/2024 Severity Critical CVE-2024-1372Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 02/13/2024 Severity Critical CVE-2024-1369Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 02/13/2024 Severity Critical CVE-2024-1359Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 02/13/2024 Severity Critical CVE-2024-1355Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 02/13/2024 Severity Critical CVE-2024-1354Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 02/13/2024 Severity High CVE-2024-1082Path traversal vulnerability in GitHub Enterprise Server that allowed arbitrary file read with a specially crafted GitHub Pages artifact upload Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 02/13/2024 Severity Medium CVE-2024-1084Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 02/13/2024 Severity Medium CVE-2024-0507Privilege Escalation by Code Injection in the Management Console in GitHub Enterprise Server Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 01/16/2024 Severity Medium CVE-2024-0200Unsafe Reflection in Github Enterprise Server leading to Command Injection Exploitation status Not known exploited Fix YesAffected product E Enterprise Server Published 01/16/2024 Severity High CVE-2024-22051CommonMarker Integer Overflow Vulnerability Exploitation status Not known exploited Fix YesAffected product C commonmarker Published 01/04/2024 Severity Critical CVE-2023-6847Improper Authentication in GitHub Enterprise Server leading to Authentication Bypass for Public Repository Data Exploitation status Not confirmed Fix YesAffected product E Enterprise Server Published 12/21/2023 Severity High