Vulnerabilidades en GitHub
160 resultadosAnálisis Vexday
Com 119 CVEs catalogadas, o GitHub apresenta taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. Ainda assim, o cenário exige atenção: 13 vulnerabilidades são de severidade crítica e CVE-2024-0200 alcança EPSS de 0,7173 — valor que indica probabilidade elevada de exploração nos próximos 30 dias, tornando-a a principal prioridade de remediação no momento. O tipo de falha mais recorrente é CWE-863 (autorização incorreta), o que sugere fragilidades recorrentes no controle de acesso que merecem revisão estrutural. As 11 CVEs surgidas nos últimos 90 dias indicam cadência ativa de descoberta, reforçando a necessidade de monitoramento contínuo mesmo na ausência de exploração confirmada.
CVE-2024-7711MEDIUMAn Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, anEPSS 0.5%CVE-2024-6395MEDIUMGitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Deploy KeysEPSS 0.5%CVE-2026-8606HIGHServer-Side Request Forgery in GitHub Enterprise Server via Advisory Package URL EndpointEPSS 0.5%CVE-2024-5566MEDIUMImproper Privilege Management allows for access to unauthorized repository content during migrationEPSS 0.5%CVE-2024-1084MEDIUMCross-site Scripting in the tag name pattern field in the tag protections UI in GitHub Enterprise Server allows a malicious website that reqEPSS 0.5%CVE-2023-51380LOWIncorrect Authorization allows Read Access to Issue Comments in GitHub Enterprise ServerEPSS 0.5%CVE-2023-23761HIGHImproper authentication vulnerability in GitHub Enterprise Server leading to modification of secret gistsEPSS 0.5%CVE-2024-2440MEDIUMRace Condition was identified in GitHub Enterprise Server that allowed maintaining admin permissionsEPSS 0.5%CVE-2024-8263MEDIUMAn improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use ofEPSS 0.4%CVE-2026-15783MEDIUMMissing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suitesEPSS 0.4%CVE-2026-47427HIGHGitHub MCP Server: Nil Pointer Dereference DoS in completion/complete HandlerEPSS 0.4%CVE-2024-8810HIGHPrivilege Management vulnerability was identified in GitHub Enterprise Server that allowed GitHub Apps to grant themselves write accessEPSS 0.4%CVE-2026-15996MEDIUMDenial of service vulnerability in GitHub Enterprise Server allowed unauthenticated service disruption via deeply nested request parametersEPSS 0.4%CVE-2026-14340MEDIUMAn incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositoriesEPSS 0.4%CVE-2026-4296HIGHIncorrect Regular Expression vulnerability in GitHub Enterprise Server allowed unauthorized access to user accounts via OAuth callback URL validation bypassEPSS 0.4%CVE-2026-5921HIGHServer-Side Request Forgery in GitHub Enterprise Server allowed extraction of sensitive environment variables via timing side-channel attackEPSS 0.4%CVE-2024-1482HIGHImproper Authorization in GitHub Enterprise Server allowed unauthorized workflow execution EPSS 0.4%CVE-2024-6336MEDIUMSecurity misconfiguration was identified in GitHub Enterprise Server that allowed sensitive data exposureEPSS 0.4%CVE-2025-3124MEDIUMMissing Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized access to private repository namesEPSS 0.4%CVE-2026-19311HIGHMissing Authorization in Execute Monitor API in OpenSearch Alerting PluginEPSS 0.4%