Vulnerability index

Browse CVEs

131 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Server HIGH 7.5
CVE-2026-15996

A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause excessive CPU consumpt…

No fix yet
Fix from $1,950 2026-08-05
Enterprise Server CRITICAL 9.1
CVE-2026-17556

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and dire…

No fix yet
Fix from $2,300 2026-08-05
Mcp Server HIGH 7.5
CVE-2026-47427

GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref withou…

Fix: 1.1.0+
Fix from $1,950 2026-07-28
Enterprise Server MEDIUM 5.0
CVE-2026-14340

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App instal…

Fix: 3.16.20 / 3.17.17+
Fix from $1,600 2026-07-01
Enterprise Server MEDIUM 5.4
CVE-2026-10585

A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to execute arbitrary Ja…

Fix: 3.16.20 / 3.17.17+
Fix from $1,600 2026-06-30
Enterprise Server MEDIUM 6.5
CVE-2026-9132

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to read source code from private …

Fix: 3.17.17 / 3.18.11+
Fix from $1,600 2026-06-30
Enterprise Server MEDIUM 5.5
CVE-2026-9106

A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an org…

Fix: 3.16.20 / 3.17.17+
Fix from $1,600 2026-06-30
Cli CRITICAL 9.1
CVE-2026-48501

GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF …

Fix: 2.93.0+
Fix from $2,300 2026-05-29
Enterprise Server HIGH 8.2
CVE-2026-9312EPSS 7%

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafte…

Fix: 3.16.19 / 3.17.16+
Fix from $1,950 2026-05-27
Enterprise Server MEDIUM 5.9
CVE-2026-8606

A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue H…

Fix: 3.16.19 / 3.17.16+
Fix from $1,600 2026-05-27
Copilot Cli HIGH 7.8
CVE-2026-45033

GitHub Copilot CLI brings AI-powered coding assistance directly to your command line. Prior to 1.0.43, a security vulnerability has been identified …

Fix: 1.0.43+
Fix from $1,950 2026-05-13
Enterprise Server CRITICAL 9.8
CVE-2026-8034

A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access …

Fix: 3.16.18 / 3.17.15+
Fix from $2,300 2026-05-07
Enterprise Server MEDIUM 6.1
CVE-2026-8106

A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page that could allow credential the…

Fix: 3.19.6 / 3.20.2+
Fix from $1,600 2026-05-07
Enterprise Server HIGH 7.5
CVE-2026-7541

A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause service disruption by …

Fix: 3.16.18 / 3.17.15+
Fix from $1,950 2026-05-07
Enterprise Server MEDIUM 6.5
CVE-2026-6736

An authentication bypass vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to create a local user acc…

Fix: 3.16.18 / 3.17.15+
Fix from $1,600 2026-05-07
Enterprise Server CRITICAL 9.6
CVE-2026-5845

An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an authenticated attac…

Fix: 3.14.26 / 3.15.21+
Fix from $2,300 2026-04-21
Enterprise Server HIGH 8.9
CVE-2026-5921

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to extract sensitive environme…

Fix: 3.14.26 / 3.15.21+
Fix from $1,950 2026-04-21
Enterprise Server HIGH 8.8
CVE-2026-4296

An incorrect regular expression vulnerability was identified in GitHub Enterprise Server that allowed an attacker to bypass OAuth redirect URI valida…

Fix: 3.14.26 / 3.15.21+
Fix from $1,950 2026-04-21
Enterprise Server MEDIUM 5.4
CVE-2026-2266

An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed DOM-based cross-site scripting via task lis…

Fix: 3.18.6 / 3.19.3+
Fix from $1,600 2026-03-10
Enterprise Server HIGH 8.8
CVE-2026-3854EPSS 34%

An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to …

Fix: 3.14.24 / 3.15.19+
Fix from $1,950 2026-03-10
Copilot Command Line Interface HIGH 7.8
CVE-2026-29783

The shell tool within GitHub Copilot CLI versions prior to and including 0.0.422 can allow arbitrary code execution through crafted bash parameter ex…

Fix: 0.0.423+
Fix from $1,950 2026-03-06
Enterprise Server MEDIUM 6.5
CVE-2026-1999

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to merge their own pull request into a r…

Fix: 3.17.11 / 3.18.5+
Fix from $1,600 2026-02-18
Enterprise Server MEDIUM 6.5
CVE-2026-1355

A Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to upload unauthorized content to another u…

Fix: 3.14.23 / 3.15.18+
Fix from $1,600 2026-02-18
Enterprise Server CRITICAL 9.0
CVE-2026-0573

An URL redirection vulnerability was identified in GitHub Enterprise Server that allowed attacker-controlled redirects to leak sensitive authorizatio…

Fix: 3.14.22 / 3.15.17+
Fix from $2,300 2026-02-18
Enterprise Server MEDIUM 5.4
CVE-2025-13744

An Improper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub Enterprise Server that allowed attacker control…

Fix: 3.14.20 / 3.15.15+
Fix from $1,600 2026-01-06
Enterprise Server MEDIUM 6.1
CVE-2025-14046

An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed user-supplied HTML to inject DOM elements w…

Fix: 3.14.21 / 3.15.16+
Fix from $1,600 2025-12-11
Enterprise Server CRITICAL 9.6
CVE-2025-11892

An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allows DOM-based cross-site scripting via Issues se…

Fix: 3.14.19 / 3.15.14+
Fix from $2,300 2025-11-10
Enterprise Server HIGH 7.2
CVE-2025-11578

A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise admin to gain root SSH acces…

Fix: 3.14.20 / 3.15.15+
Fix from $1,950 2025-11-10
Enterprise Server HIGH 7.6
CVE-2025-3246

An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site scripting in GitHub Markdown tha…

Mitigation only
Fix from $1,950 2025-04-17
Enterprise Server HIGH 7.2
CVE-2025-3509

A Remote Code Execution (RCE) vulnerability was identified in GitHub Enterprise Server that allowed attackers to execute arbitrary code by exploiting…

Fix: 3.13.16 / 3.14.13+
Fix from $1,950 2025-04-17