Vulnerabilities in GitHub

151 results
Vexday analysis

Com 119 CVEs catalogadas, o GitHub apresenta taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. Ainda assim, o cenário exige atenção: 13 vulnerabilidades são de severidade crítica e CVE-2024-0200 alcança EPSS de 0,7173 — valor que indica probabilidade elevada de exploração nos próximos 30 dias, tornando-a a principal prioridade de remediação no momento. O tipo de falha mais recorrente é CWE-863 (autorização incorreta), o que sugere fragilidades recorrentes no controle de acesso que merecem revisão estrutural. As 11 CVEs surgidas nos últimos 90 dias indicam cadência ativa de descoberta, reforçando a necessidade de monitoramento contínuo mesmo na ausência de exploração confirmada.

CVE-2024-2440MEDIUMRace Condition was identified in GitHub Enterprise Server that allowed maintaining admin permissionsEPSS 0.5%CVE-2024-8263MEDIUMAn improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use ofEPSS 0.4%CVE-2026-15343HIGHPath traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot dependency-file pathsEPSS 0.4%CVE-2024-8810HIGHPrivilege Management vulnerability was identified in GitHub Enterprise Server that allowed GitHub Apps to grant themselves write accessEPSS 0.4%CVE-2026-4296HIGHIncorrect Regular Expression vulnerability in GitHub Enterprise Server allowed unauthorized access to user accounts via OAuth callback URL validation bypassEPSS 0.4%CVE-2026-5921HIGHServer-Side Request Forgery in GitHub Enterprise Server allowed extraction of sensitive environment variables via timing side-channel attackEPSS 0.4%CVE-2024-1482HIGHImproper Authorization in GitHub Enterprise Server allowed unauthorized workflow execution EPSS 0.4%CVE-2024-6336MEDIUMSecurity misconfiguration was identified in GitHub Enterprise Server that allowed sensitive data exposureEPSS 0.4%CVE-2025-3124MEDIUMMissing Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized access to private repository namesEPSS 0.4%CVE-2026-47427HIGHGitHub MCP Server: Nil Pointer Dereference DoS in completion/complete HandlerEPSS 0.4%CVE-2021-32638MEDIUMCodeQL runner: Command-line options that make GitHub access tokens visible to other processes are now deprecatedEPSS 0.4%CVE-2026-15996MEDIUMDenial of service vulnerability in GitHub Enterprise Server allowed unauthenticated service disruption via deeply nested request parametersEPSS 0.4%CVE-2026-1355MEDIUMMissing Authorization Check in GitHub Enterprise Server Allows Unauthorized Uploads to Repository Migration ExportsEPSS 0.4%CVE-2026-7541MEDIUMDenial of service vulnerability in GitHub Enterprise Server allowed service disruption via unauthenticated API endpointEPSS 0.4%CVE-2026-8606HIGHServer-Side Request Forgery in GitHub Enterprise Server via Advisory Package URL EndpointEPSS 0.4%CVE-2024-10001HIGHCode Injection Vulnerability in GitHub Enterprise Server Allows Arbitrary Code Execution via Message HandlingEPSS 0.4%CVE-2026-8034HIGHServer-side request forgery vulnerability in GitHub Enterprise Server notebook viewer via URL parser confusionEPSS 0.4%CVE-2025-14046HIGHInsufficient HTML Sanitization Allows User-Controlled DOM Elements to Overwrite Server-Initialized Data Islands and Trigger Unintended Server-Side POST RequestsEPSS 0.4%CVE-2026-15007MEDIUMDenial of service vulnerability in GitHub Enterprise Server allowed service disruption via deeply nested YAML in release notes configurationEPSS 0.4%CVE-2026-29783HIGHGitHub Copilot CLI allows for dangerous shell expansion patterns that enable arbitrary command executionEPSS 0.4%