SecAlerts
G

GitHub

Security Risk Profile

48
/100
medium

Security Risk Score

Comprehensive risk assessment based on 215 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from April 4, 2012 to present

215
Total CVEs
104
Critical+High
12
Exploited
82
Unpatched

Threat Assessment

Avg CVSS
7.2
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
82
Critical/High
Risk Level
48/100
medium
⚠️ 12 Active Exploits🆕 1Fresh (<7d)📈 5 in Last 30 Days

Severity Distribution

Critical
30
High
74
Medium
75
Low
7

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
1
<5%
55

Age Distribution

Common Weaknesses (CWE)

1
Command Injection
22
2
Path Traversal
17
3
Input Validation
15
4
XSS
13
5
SSRF
10

Most Affected Products

1. GitHub Enterprise Server294
2. github Enterprise Server271
3. GitHub GitHub Enterprise Server38
4. GitHub GitHub29
5. cmark-gfm10

Recent Vulnerabilities

See more →
CVE-2026-94620
CVSS 9.4critical

Classroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download)

Oct 1, 2026🔧 No Patch
CVE-2026-75101
CVSS 6.0medium

Authorization bypass vulnerability in GitHub Enterprise Server allowed reading of private pull request diffs and patches via repository name collision

Sep 22, 2026🔧 No Patch
CVE-2026-77912
CVSS 7.4high

Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed HTML attribute injection via the Markdown rendering pipeline

Sep 22, 2026🔧 No Patch
CVE-2026-77987
CVSS 9.3critical

GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgery

Sep 22, 2026🔧 No Patch
GHSL-2026-225
unknown

Artifact metadata injection in actions/attest

Sep 16, 2026🔧 No Patch
CVE-2026-76851
CVSS 7.7high

Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed remote code execution via network access from pre-receive hooks to internal services

Sep 1, 2026🔧 No Patch
CVE-2026-19118
CVSS 7.7high

Race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution

Sep 1, 2026🔧 No Patch
CVE-2026-18730
CVSS 8.2high

Server-side request forgery vulnerability in GitHub Enterprise Server Manage API leaked a replayable gateway-agent bearer token

Sep 1, 2026🔧 No Patch
CVE-2026-72924
CVSS 2.1low

GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default

Aug 25, 2026
CVE-2026-70335
CVSS 7.8high

GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability

Aug 11, 2026

Monitor GitHub in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

GitHub Security Vulnerabilities & Risk Score | 215 CVEs | SecAlerts - SecAlerts