SecAlerts
GitHub logo

GitHub

Security Risk Profile

43
/100
medium

Security Risk Score

Comprehensive risk assessment based on 198 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from April 4, 2012 to present

198
Total CVEs
95
Critical+High
12
Exploited
75
Unpatched

Threat Assessment

Avg CVSS
7.2
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
75
Critical/High
Risk Level
43/100
medium
⚠️ 12 Active Exploits📈 5 in Last 30 Days

Severity Distribution

Critical
28
High
67
Medium
71
Low
4

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
1
<5%
55

Age Distribution

Common Weaknesses (CWE)

1
Command Injection
21
2
Input Validation
15
3
Path Traversal
14
4
XSS
12
5
Infoleak
9

Most Affected Products

1. github Enterprise Server271
2. GitHub Enterprise Server253
3. GitHub GitHub Enterprise Server30
4. GitHub GitHub29
5. cmark-gfm10

Recent Vulnerabilities

See more →
CVE-2026-15783
CVSS 5.3medium

Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suites

7/17/2026🔧 No Patch
CVE-2026-15343
CVSS 8.6high

Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot dependency-file paths

7/17/2026🔧 No Patch
CVE-2026-15007
CVSS 5.7medium

Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via deeply nested YAML in release notes configuration

7/17/2026🔧 No Patch
CVE-2026-59831
CVSS 4.4medium

GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious Codespace

7/9/2026
darkreading-20260707152430
unknown

'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows

7/7/2026⚠ Exploited🔧 No Patch
CVE-2026-14340
CVSS 5.3medium

An incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositories

7/1/2026🔧 No Patch
CVE-2026-10585
CVSS 6.3medium

Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed arbitrary JavaScript execution via crafted Discussion titles in the Q&A category

6/30/2026🔧 No Patch
CVE-2026-9132
CVSS 6.0EPSS 0%medium

Missing authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository contents via the Copilot pull request diff summary endpoint

6/30/2026🔧 No Patch
CVE-2026-9106
CVSS 4.8EPSS 0%medium

UI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organization runner management via undisclosed OAuth scope on consent screen

6/30/2026🔧 No Patch
CVE-2025-66389
CVSS 7.5high
6/22/2026🔧 No Patch

Monitor GitHub in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

GitHub Security Vulnerabilities & Risk Score | 198 CVEs | SecAlerts - SecAlerts