GitHub's vulnerability footprint spans a focused but strategically important portfolio of development and collaboration platforms, including GitHub Enterprise Server and its command-line interface, that sit in the software supply chain and development pipelines of countless organizations. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, while the exposure recurs through weakness classes including command injection, input validation flaws, authorization bypasses, and path traversal that are characteristic of web applications and automation tooling. The relatively narrow product scope contrasts with the vendor's prominence in the landscape, reflecting how centrally these platforms sit in code management, CI/CD orchestration, and secrets handling across enterprises and open-source ecosystems. Defenders should treat GitHub advisories as high-priority, particularly those affecting Enterprise Server instances and the CLI, since supply-chain implications can amplify exposure across development teams. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Github over time
Signals from CVEs in this vendor scope (154 CVEs).
154 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-0200CRITICAL An unsafe reflection vulnerability was identified in GitHub Enterprise Server that could lead to reflection injection. This vulnerability could lead to the execution of user-contro | Jan 16, 2024 | 9.8 | 80 | NO | YES |
CVE-2024-0507HIGH An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. Thi | Jan 16, 2024 | 8.8 | 63 | NO | NO |
CVE-2026-3854HIGH An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to a repository to achieve remote | Mar 10, 2026 | 8.8 | 62 | NO | NO |
CVE-2017-18365CRITICAL The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to execute arbitrary code. This occurs becau | Mar 28, 2019 | 9.8 | 55 | NO | YES |
CVE-2024-9487CRITICAL An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauth | Oct 10, 2024 | 9.1 | 54 | NO | YES |
CVE-2026-9312HIGH A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services | May 27, 2026 | 8.2 | 40 | NO | NO |
CVE-2026-15343HIGH A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to | Jul 17, 2026 | 8.6 | 36 | NO | NO |
CVE-2026-8034CRITICAL A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access internal services by exploiting | May 7, 2026 | 9.8 | 36 | NO | NO |
CVE-2024-42471HIGH actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when usi | Sep 2, 2024 | 7.5 | 35 | NO | YES |
CVE-2024-6800CRITICAL An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity providers utilizing publicly exposed si | Aug 20, 2024 | 9.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (154 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Github.
Media articles that mention a CVE ID that affects a product developed by Github — matched by CVE ID, not by vendor name.