GitHub, Inc. (Products Only)
First CVE: Jun 3, 2020Active for: 6 years
126
CVEs Published
More CVEs Published than 73% of tracked CNAs
18.0
Avg CVEs / Year
More Avg CVEs / Year than 65% of tracked CNAs
6.8
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by GitHub, Inc. (Products Only) over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 3, 2020
6 years ago
Most Recent CVE
Jul 17, 2026
7 days ago
Top CVEs
All CVEs published by GitHub, Inc. (Products Only) as a CNA, regardless of affected vendor or product.
126 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-0200CRITICAL An unsafe reflection vulnerability was identified in GitHub Enterprise Server that could lead to reflection injection. This vulnerability could lead to the execution of user-contro | Jan 16, 2024 | 9.8 | 80 | NO | YES |
CVE-2024-0507HIGH An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. Thi | Jan 16, 2024 | 8.8 | 63 | NO | NO |
CVE-2026-3854HIGH An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to a repository to achieve remote | Mar 10, 2026 | 8.8 | 62 | NO | NO |
CVE-2024-9487CRITICAL An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauth | Oct 10, 2024 | 9.1 | 54 | NO | YES |
CVE-2026-9312HIGH A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services | May 27, 2026 | 8.2 | 40 | NO | NO |
CVE-2026-15343HIGH A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to | Jul 17, 2026 | 8.6 | 36 | NO | NO |
CVE-2026-8034CRITICAL A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access internal services by exploiting | May 7, 2026 | 9.8 | 36 | NO | NO |
CVE-2024-6800CRITICAL An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity providers utilizing publicly exposed si | Aug 20, 2024 | 9.8 | 33 | NO | NO |
CVE-2026-0573CRITICAL An URL redirection vulnerability was identified in GitHub Enterprise Server that allowed attacker-controlled redirects to leak sensitive authorization tokens. The repository_pages | Feb 18, 2026 | 9.0 | 32 | NO | NO |
CVE-2024-4985CRITICAL An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication with the optional encrypted assertions f | May 20, 2024 | 9.8 | 32 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA126 CVEs
52%
30%
15%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (2.4%)
Network123 (97.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low114 (90.5%)
High12 (9.5%)
Unknown0 (0.0%)
User Interaction
None99 (78.6%)
Unknown0 (0.0%)
Required27 (21.4%)
Privileges Required
Low64 (50.8%)
High26 (20.6%)
None36 (28.6%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (126 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
1.6% of CVEs· 83rd percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by GitHub, Inc. (Products Only) as a CNA.
Media Mentions
Media articles that mention a CVE ID published by GitHub, Inc. (Products Only) as a CNA — matched by CVE ID, not by organization name.