SecAlerts
G

GitHub

Security Risk Profile

42
/100
medium

Security Risk Score

Comprehensive risk assessment based on 206 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from April 4, 2012 to present

206
Total CVEs
98
Critical+High
12
Exploited
76
Unpatched

Threat Assessment

Avg CVSS
7.2
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
76
Critical/High
Risk Level
42/100
medium
⚠️ 12 Active Exploits📈 8 in Last 30 Days

Severity Distribution

Critical
28
High
70
Medium
74
Low
6

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
1
<5%
55

Age Distribution

Common Weaknesses (CWE)

1
Command Injection
22
2
Path Traversal
16
3
Input Validation
15
4
XSS
12
5
Infoleak
9

Most Affected Products

1. github Enterprise Server271
2. GitHub Enterprise Server262
3. GitHub GitHub Enterprise Server32
4. GitHub GitHub29
5. cmark-gfm10

Recent Vulnerabilities

See more →
CVE-2026-70335
CVSS 7.8high

GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability

Aug 11, 2026
CVE-2026-64655
CVSS 2.1low

GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN Matching

Aug 6, 2026
CVE-2026-64654
CVSS 5.3medium

GitHub CLI: Terminal escape sequence injection in multiple `gh` commands

Aug 6, 2026
CVE-2026-64653
CVSS 5.1medium

GitHub CLI: Unescaped variable components in request URLs could allow path traversal

Aug 6, 2026
CVE-2026-64652
CVSS 3.3low

GitHub CLI: Partial token disclosure in `gh auth status` output

Aug 6, 2026
CVE-2026-15996
CVSS 6.6medium

Denial of service vulnerability in GitHub Enterprise Server allowed unauthenticated service disruption via deeply nested request parameters

Aug 5, 2026🔧 No Patch
CVE-2026-17556
CVSS 8.8high

Path traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance storage via the X-GitHub-Request-Id header

Aug 5, 2026🔧 No Patch
CVE-2026-47427
CVSS 7.5high

GitHub MCP Server: Nil Pointer Dereference DoS in completion/complete Handler

Jul 28, 2026
CVE-2026-15783
CVSS 5.3medium

Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suites

Jul 17, 2026🔧 No Patch
CVE-2026-15343
CVSS 8.6high

Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot dependency-file paths

Jul 17, 2026🔧 No Patch

Monitor GitHub in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.