Vulnerabilities in GitHub
160 resultsVexday analysis
Com 119 CVEs catalogadas, o GitHub apresenta taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. Ainda assim, o cenário exige atenção: 13 vulnerabilidades são de severidade crítica e CVE-2024-0200 alcança EPSS de 0,7173 — valor que indica probabilidade elevada de exploração nos próximos 30 dias, tornando-a a principal prioridade de remediação no momento. O tipo de falha mais recorrente é CWE-863 (autorização incorreta), o que sugere fragilidades recorrentes no controle de acesso que merecem revisão estrutural. As 11 CVEs surgidas nos últimos 90 dias indicam cadência ativa de descoberta, reforçando a necessidade de monitoramento contínuo mesmo na ausência de exploração confirmada.
CVE-2026-9132MEDIUMMissing authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository contents via the Copilot pull request diff summary endpointEPSS 0.4%CVE-2026-1355MEDIUMMissing Authorization Check in GitHub Enterprise Server Allows Unauthorized Uploads to Repository Migration ExportsEPSS 0.4%CVE-2021-32638MEDIUMCodeQL runner: Command-line options that make GitHub access tokens visible to other processes are now deprecatedEPSS 0.4%CVE-2026-7541MEDIUMDenial of service vulnerability in GitHub Enterprise Server allowed service disruption via unauthenticated API endpointEPSS 0.4%CVE-2025-14046HIGHInsufficient HTML Sanitization Allows User-Controlled DOM Elements to Overwrite Server-Initialized Data Islands and Trigger Unintended Server-Side POST RequestsEPSS 0.4%CVE-2024-10001HIGHCode Injection Vulnerability in GitHub Enterprise Server Allows Arbitrary Code Execution via Message HandlingEPSS 0.4%CVE-2026-18952HIGHMissing Input Validation in Threat Intel Feed Parser in OpenSearch Security Analytics PluginEPSS 0.4%CVE-2024-8770MEDIUMA Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attacEPSS 0.4%CVE-2026-9106MEDIUMUI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organization runner management via undisclosed OAuth scope on consent screenEPSS 0.4%CVE-2026-29783HIGHGitHub Copilot CLI allows for dangerous shell expansion patterns that enable arbitrary command executionEPSS 0.4%CVE-2026-3306MEDIUMImproper authorization in GitHub Projects allows modification of issue and pull request metadata without repository write accessEPSS 0.4%CVE-2026-45033HIGHGitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitorEPSS 0.4%CVE-2024-10824MEDIUMAuthorization Bypass Vulnerability was Identified in GitHub Enterprise Server that Allowed Unauthorized Internal Users to Access Secret Scanning Alert DataEPSS 0.3%CVE-2026-1999HIGHIncorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized merging of pull requestsEPSS 0.3%CVE-2023-6690LOWA race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on transferred repositories by making a GraphEPSS 0.3%CVE-2026-10585MEDIUMStored cross-site scripting vulnerability in GitHub Enterprise Server allowed arbitrary JavaScript execution via crafted Discussion titles in the Q&A categoryEPSS 0.3%CVE-2025-8447HIGHIncorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed read-only accessEPSS 0.3%CVE-2025-6600MEDIUMGitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Search APIEPSS 0.3%CVE-2025-3246HIGHMarkdown math block sanitization bypass allows privilege escalation and unauthorized workflow triggersEPSS 0.3%CVE-2026-5512MEDIUMImproper authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository names via mobile upload policy APIEPSS 0.3%