Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Github

First CVE: Apr 5, 2012Active for: 14 yearsTotal CVEs: 154
45.3
VTI Score
High

GitHub's vulnerability footprint spans a focused but strategically important portfolio of development and collaboration platforms, including GitHub Enterprise Server and its command-line interface, that sit in the software supply chain and development pipelines of countless organizations. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, while the exposure recurs through weakness classes including command injection, input validation flaws, authorization bypasses, and path traversal that are characteristic of web applications and automation tooling. The relatively narrow product scope contrasts with the vendor's prominence in the landscape, reflecting how centrally these platforms sit in code management, CI/CD orchestration, and secrets handling across enterprises and open-source ecosystems. Defenders should treat GitHub advisories as high-priority, particularly those affecting Enterprise Server instances and the CLI, since supply-chain implications can amplify exposure across development teams. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
154
Total CVEs
More Total CVEs than 100% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Github over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 5, 2012
14 years ago
Most Recent CVE
Jul 17, 2026
7 days ago

Products(18 total)

Top CVEs

Signals from CVEs in this vendor scope (154 CVEs).

154 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-0200CRITICAL
An unsafe reflection vulnerability was identified in GitHub Enterprise Server that could lead to reflection injection. This vulnerability could lead to the execution of user-contro
Jan 16, 20249.880NOYES
CVE-2024-0507HIGH
An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. Thi
Jan 16, 20248.863NONO
CVE-2026-3854HIGH
An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to a repository to achieve remote
Mar 10, 20268.862NONO
CVE-2017-18365CRITICAL
The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to execute arbitrary code. This occurs becau
Mar 28, 20199.855NOYES
CVE-2024-9487CRITICAL
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauth
Oct 10, 20249.154NOYES
CVE-2026-9312HIGH
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services
May 27, 20268.240NONO
CVE-2026-15343HIGH
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to
Jul 17, 20268.636NONO
CVE-2026-8034CRITICAL
A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access internal services by exploiting
May 7, 20269.836NONO
CVE-2024-42471HIGH
actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when usi
Sep 2, 20247.535NOYES
CVE-2024-6800CRITICAL
An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity providers utilizing publicly exposed si
Aug 20, 20249.833NONO
View all 154 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products154 CVEs
47%
32%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local8 (5.2%)
Network144 (93.5%)
Unknown2 (1.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low140 (90.9%)
High12 (7.8%)
Unknown2 (1.3%)
User Interaction
None118 (76.6%)
Unknown2 (1.3%)
Required34 (22.1%)
Privileges Required
Low69 (44.8%)
High27 (17.5%)
None56 (36.4%)
Unknown2 (1.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (154 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.6% of CVEs· 97th percentile
Nuclei
2 CVEs
1.3% of CVEs· 95th percentile
ExploitDB
1 CVE
0.6% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Github.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Github — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Github's Products

View all 7 CNAs →

Top CWEs