CVE-2026-76851Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed remote code execution via network access from pre-receive hooks to internal services Exploitation status Not known exploited Fix YesPublished 09/01/2026 Severity High CVE-2026-19118Race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution Exploitation status Not known exploited Fix YesPublished 09/01/2026 Severity High CVE-2026-18730Server-side request forgery vulnerability in GitHub Enterprise Server Manage API leaked a replayable gateway-agent bearer token Exploitation status Not known exploited Fix YesPublished 09/01/2026 Severity High CVE-2026-15996Denial of service vulnerability in GitHub Enterprise Server allowed unauthenticated service disruption via deeply nested request parameters Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity Medium CVE-2026-17556Path traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance storage via the X-GitHub-Request-Id header Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity High CVE-2026-15783Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suites Exploitation status Not known exploited Fix YesPublished 07/17/2026 Severity Medium CVE-2026-15343Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot dependency-file paths Exploitation status Not known exploited Fix YesPublished 07/17/2026 Severity High CVE-2026-15007Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via deeply nested YAML in release notes configuration Exploitation status Not known exploited Fix YesPublished 07/17/2026 Severity Medium CVE-2026-14340An incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositories Exploitation status Not known exploited Fix YesPublished 07/01/2026 Severity Medium CVE-2026-10585Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed arbitrary JavaScript execution via crafted Discussion titles in the Q&A category Exploitation status Not known exploited Fix YesPublished 06/30/2026 Severity Medium CVE-2026-9132Missing authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository contents via the Copilot pull request diff summary endpoint Exploitation status Not known exploited Fix YesPublished 06/30/2026 Severity Medium CVE-2026-9106UI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organization runner management via undisclosed OAuth scope on consent screen Exploitation status Not known exploited Fix YesPublished 06/30/2026 Severity Medium CVE-2026-9312Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to internal services via path traversal in upload endpoint Exploitation status Not known exploited Fix YesPublished 05/27/2026 Severity Critical CVE-2026-8606Server-Side Request Forgery in GitHub Enterprise Server via Advisory Package URL Endpoint Exploitation status Not known exploited Fix YesPublished 05/26/2026 Severity High CVE-2026-8106Reflected HTML injection vulnerability in GitHub Enterprise Server Management Console login page allowed credential theft Exploitation status Not known exploited Fix YesPublished 05/07/2026 Severity Medium CVE-2026-8034Server-side request forgery vulnerability in GitHub Enterprise Server notebook viewer via URL parser confusion Exploitation status Not known exploited Fix YesPublished 05/07/2026 Severity High CVE-2026-7541Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via unauthenticated API endpoint Exploitation status Not known exploited Fix YesPublished 05/07/2026 Severity Medium CVE-2026-6736Authentication bypass vulnerability in GitHub Enterprise Server allowed creation of local user accounts bypassing the configured external identity provider Exploitation status Not known exploited Fix YesPublished 05/07/2026 Severity Medium CVE-2026-5845Improper authorization fallback allows scoped user-to-server token installation escape in GitHub Enterprise Server Exploitation status Not known exploited Fix YesPublished 04/21/2026 Severity High CVE-2026-3307Authorization bypass in GitHub Enterprise Server secret scanning push protection allows cross-repository modification of delegated bypass reviewers Exploitation status Not known exploited Fix YesPublished 04/21/2026 Severity Medium CVE-2026-5512Improper authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository names via mobile upload policy API Exploitation status Not known exploited Fix YesPublished 04/21/2026 Severity Medium CVE-2026-4296Incorrect Regular Expression vulnerability in GitHub Enterprise Server allowed unauthorized access to user accounts via OAuth callback URL validation bypass Exploitation status Not known exploited Fix YesPublished 04/21/2026 Severity High CVE-2026-4821Exploitation status Not confirmed Fix Not confirmed Published 04/21/2026 Severity Unknown CVE-2026-5921Server-Side Request Forgery in GitHub Enterprise Server allowed extraction of sensitive environment variables via timing side-channel attack Exploitation status Not known exploited Fix YesPublished 04/21/2026 Severity High CVE-2026-3582Incorrect Authorization in GitHub Enterprise Server allows access to issue and commit search results without repo scope Exploitation status Not known exploited Fix YesPublished 03/10/2026 Severity Medium CVE-2026-2266Improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site scripting via task list content and enabled arbitrary HTML injection Exploitation status Not known exploited Fix YesPublished 03/10/2026 Severity High CVE-2026-3306Improper authorization in GitHub Projects allows modification of issue and pull request metadata without repository write access Exploitation status Not known exploited Fix YesPublished 03/10/2026 Severity Medium CVE-2026-3854Remote code execution via git push option injection in GitHub Enterprise Server Exploitation status Not known exploited Fix YesPublished 03/10/2026 Severity High CVE-2026-1999Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized merging of pull requests Exploitation status Not known exploited Fix YesPublished 02/18/2026 Severity High CVE-2026-1355Missing Authorization Check in GitHub Enterprise Server Allows Unauthorized Uploads to Repository Migration Exports Exploitation status Not known exploited Fix YesPublished 02/18/2026 Severity Medium CVE-2026-0573Improper Handling of HTTP Redirects vulnerability was identified in GitHub Enterprise Server that allowed leaking of authorization token and enabled remote code execution Exploitation status Not known exploited Fix YesPublished 02/18/2026 Severity High CVE-2025-13744Improper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub Enterprise Server that allowed rendering of malicious HTML Exploitation status Not known exploited Fix YesPublished 01/06/2026 Severity High CVE-2025-14046Insufficient HTML Sanitization Allows User-Controlled DOM Elements to Overwrite Server-Initialized Data Islands and Trigger Unintended Server-Side POST Requests Exploitation status Not known exploited Fix YesPublished 12/11/2025 Severity High CVE-2025-11578Pre-Receive Hook Path Collision Vulnerability in GitHub Enterprise Server Allowing Privilege Escalation Exploitation status Not known exploited Fix YesPublished 11/10/2025 Severity High CVE-2025-11892DOM-based Cross-Site Scripting was identified in GitHub Enterprise Server Issues search allows privilege escalation and unauthorized workflow triggers Exploitation status Not known exploited Fix YesPublished 11/10/2025 Severity High CVE-2025-8447Incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed read-only access Exploitation status Not known exploited Fix YesPublished 08/26/2025 Severity High CVE-2025-6981Incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized read-only access Exploitation status Not known exploited Fix YesPublished 07/15/2025 Severity Medium CVE-2025-3509Pre-Receive Hook Remote Code Execution vulnerability was identified in GitHub Enterprise Server that allowing Privilege Escalation Exploitation status Not known exploited Fix YesPublished 04/17/2025 Severity High CVE-2025-3124Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized access to private repository names Exploitation status Not known exploited Fix YesPublished 04/17/2025 Severity Medium CVE-2024-10001Code Injection Vulnerability in GitHub Enterprise Server Allows Arbitrary Code Execution via Message Handling Exploitation status Not known exploited Fix YesPublished 01/29/2025 Severity High CVE-2025-23369Improper Verification of Cryptographic Signature in GitHub Enterprise Server Allows Signature Spoofing by Improper Validation Exploitation status Not known exploited Fix YesPublished 01/21/2025 Severity High CVE-2024-8810Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed GitHub Apps to grant themselves write access Exploitation status Not known exploited Fix YesPublished 11/07/2024 Severity High CVE-2024-10824Authorization Bypass Vulnerability was Identified in GitHub Enterprise Server that Allowed Unauthorized Internal Users to Access Secret Scanning Alert Data Exploitation status Not known exploited Fix YesPublished 11/07/2024 Severity Medium CVE-2024-10007Pre-Receive Hook Path Collision Vulnerability in GitHub Enterprise Server Allowing Privilege Escalation Exploitation status Not known exploited Fix YesPublished 11/07/2024 Severity High CVE-2024-9487An Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed when the encrypted assertions feature was enabled Exploitation status Not known exploited Fix YesPublished 10/10/2024 Severity Critical CVE-2024-4985Exploitation status Public exploit Fix YesPublished 05/20/2024 Severity Critical CVE-2024-2440Race Condition was identified in GitHub Enterprise Server that allowed maintaining admin permissions Exploitation status Not known exploited Fix YesPublished 04/19/2024 Severity Medium CVE-2024-3684Improper Privilege Management was identified in GitHub Enterprise Server that allowed privilege escalation in the Management Console Exploitation status Not known exploited Fix YesPublished 04/19/2024 Severity High CVE-2024-3646Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Management Console Exploitation status Not known exploited Fix YesPublished 04/19/2024 Severity High CVE-2024-3470Repository administrator can bypass organization's ruleset using deploy keys Exploitation status Not known exploited Fix YesPublished 04/19/2024 Severity Medium CVE-2024-2748CSRF vulnerability was identified in GitHub Enterprise Server that allowed performing actions on behalf of a user Exploitation status Not known exploited Fix YesPublished 03/20/2024 Severity Medium CVE-2024-2469Remote Code Execution in GitHub Enterprise Server Allowed Administrators to gain SSH access to the appliance Exploitation status Not known exploited Fix YesPublished 03/20/2024 Severity High CVE-2024-1908Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed Privilege Escalation Exploitation status Not known exploited Fix YesPublished 02/29/2024 Severity Medium CVE-2024-1482Improper Authorization in GitHub Enterprise Server allowed unauthorized workflow execution Exploitation status Not known exploited Fix YesPublished 02/14/2024 Severity High CVE-2024-1378Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console Exploitation status Not known exploited Fix YesPublished 02/13/2024 Severity Critical CVE-2024-1374Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console Exploitation status Not known exploited Fix YesPublished 02/13/2024 Severity Critical CVE-2024-1372Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console Exploitation status Not known exploited Fix YesPublished 02/13/2024 Severity Critical CVE-2024-1369Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console Exploitation status Not known exploited Fix YesPublished 02/13/2024 Severity Critical CVE-2024-1359Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console Exploitation status Not known exploited Fix YesPublished 02/13/2024 Severity Critical CVE-2024-1355Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console Exploitation status Not known exploited Fix YesPublished 02/13/2024 Severity Critical CVE-2024-1354Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console Exploitation status Not known exploited Fix YesPublished 02/13/2024 Severity High CVE-2024-1082Path traversal vulnerability in GitHub Enterprise Server that allowed arbitrary file read with a specially crafted GitHub Pages artifact upload Exploitation status Not known exploited Fix YesPublished 02/13/2024 Severity Medium CVE-2024-1084Exploitation status Not known exploited Fix YesPublished 02/13/2024 Severity Medium CVE-2024-0507Privilege Escalation by Code Injection in the Management Console in GitHub Enterprise Server Exploitation status Not known exploited Fix YesPublished 01/16/2024 Severity Medium CVE-2024-0200Unsafe Reflection in Github Enterprise Server leading to Command Injection Exploitation status Not known exploited Fix YesPublished 01/16/2024 Severity High CVE-2023-6847Improper Authentication in GitHub Enterprise Server leading to Authentication Bypass for Public Repository Data Exploitation status Not confirmed Fix YesPublished 12/21/2023 Severity High CVE-2023-51380Incorrect Authorization allows Read Access to Issue Comments in GitHub Enterprise Server Exploitation status Not confirmed Fix YesPublished 12/21/2023 Severity Low CVE-2023-51379Incorrect Authorization for Issue Comments in GitHub Enterprise Server Exploitation status Not confirmed Fix YesPublished 12/21/2023 Severity Medium CVE-2023-46648Insufficient Entropy in GitHub Enterprise Server Management Console Invitation Token Exploitation status Not confirmed Fix YesPublished 12/21/2023 Severity High CVE-2023-46649Race Condition allows Administrative Access on Organization Repositories Exploitation status Not confirmed Fix YesPublished 12/21/2023 Severity Medium CVE-2023-6804Improper Privilege Management allows for arbitrary workflows to be run Exploitation status Not known exploited Fix YesPublished 12/21/2023 Severity Medium CVE-2023-6803Race Condition allows Unauthorized Outside Collaborator Exploitation status Not confirmed Fix YesPublished 12/21/2023 Severity Medium CVE-2023-6802Sensitive Information in Log File in GitHub Enterprise Server Exploitation status Not known exploited Fix YesPublished 12/21/2023 Severity High CVE-2023-6746Sensitive Information in Log File in GitHub Enterprise Server Exploitation status Not known exploited Fix YesPublished 12/21/2023 Severity High CVE-2023-46645Path traversal in GitHub Enterprise Server leading to arbitrary file reading when building a GitHub Pages site Exploitation status Not known exploited Fix YesPublished 12/21/2023 Severity Medium CVE-2023-6690Exploitation status Not confirmed Fix YesPublished 12/21/2023 Severity Low CVE-2023-46647Improper Privilege Management in GitHub Enterprise Server management console leads to privilege escalation Exploitation status Not confirmed Fix YesPublished 12/21/2023 Severity High CVE-2023-46646Exploitation status Not known exploited Fix YesPublished 12/21/2023 Severity Medium CVE-2023-23766Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling Exploitation status Not known exploited Fix YesPublished 09/22/2023 Severity Medium CVE-2023-23763Information disclosure in GitHub Enterprise Server leading to private repository leakage Exploitation status Not known exploited Fix YesPublished 09/01/2023 Severity Medium CVE-2023-23765Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling Exploitation status Not known exploited Fix YesPublished 08/30/2023 Severity Medium CVE-2023-23764Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling Exploitation status Not known exploited Fix YesPublished 07/27/2023 Severity Medium CVE-2023-23762Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling Exploitation status Not known exploited Fix YesPublished 04/07/2023 Severity Medium CVE-2023-23761Improper authentication vulnerability in GitHub Enterprise Server leading to modification of secret gists Exploitation status Not known exploited Fix YesPublished 04/07/2023 Severity High CVE-2023-23760Path traversal in GitHub Enterprise Server leading to remote code execution Exploitation status Not known exploited Fix YesPublished 03/08/2023 Severity Medium CVE-2023-22381Code injection in GitHub Enterprise Server leading to arbitrary environment variables in GitHub Actions Exploitation status Not known exploited Fix YesPublished 03/02/2023 Severity Medium