Vulnerabilidades em GitHub

160 resultados
Análise Vexday

Com 119 CVEs catalogadas, o GitHub apresenta taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. Ainda assim, o cenário exige atenção: 13 vulnerabilidades são de severidade crítica e CVE-2024-0200 alcança EPSS de 0,7173 — valor que indica probabilidade elevada de exploração nos próximos 30 dias, tornando-a a principal prioridade de remediação no momento. O tipo de falha mais recorrente é CWE-863 (autorização incorreta), o que sugere fragilidades recorrentes no controle de acesso que merecem revisão estrutural. As 11 CVEs surgidas nos últimos 90 dias indicam cadência ativa de descoberta, reforçando a necessidade de monitoramento contínuo mesmo na ausência de exploração confirmada.

CVE-2026-18730HIGHServer-side request forgery vulnerability in GitHub Enterprise Server Manage API leaked a replayable gateway-agent bearer tokenEPSS 0.3%CVE-2026-5845HIGHImproper authorization fallback allows scoped user-to-server token installation escape in GitHub Enterprise ServerEPSS 0.3%CVE-2026-54163MEDIUMsecure_headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted inputEPSS 0.3%CVE-2026-3307MEDIUMAuthorization bypass in GitHub Enterprise Server secret scanning push protection allows cross-repository modification of delegated bypass reviewersEPSS 0.3%CVE-2025-6981MEDIUMIncorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized read-only accessEPSS 0.3%CVE-2026-6736MEDIUMAuthentication bypass vulnerability in GitHub Enterprise Server allowed creation of local user accounts bypassing the configured external identity providerEPSS 0.3%CVE-2024-5815MEDIUMCross Site Request Forgery was identified in GitHub Enterprise Server that allowed write in a user owned repositoryEPSS 0.3%CVE-2026-3582MEDIUMIncorrect Authorization in GitHub Enterprise Server allows access to issue and commit search results without repo scopeEPSS 0.2%CVE-2018-25188HIGHWebiness Inventory 2.3 SQL Injection via WsModelGrid.phpEPSS 0.2%CVE-2025-13744HIGHImproper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub Enterprise Server that allowed rendering of malicious HTMLEPSS 0.2%CVE-2026-48529MEDIUMGitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusionEPSS 0.2%CVE-2023-6804MEDIUMImproper Privilege Management allows for arbitrary workflows to be runEPSS 0.2%CVE-2024-2748MEDIUMCSRF vulnerability was identified in GitHub Enterprise Server that allowed performing actions on behalf of a userEPSS 0.2%CVE-2026-2266HIGHImproper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site scripting via task list content and enabled arbitrary HTML injectionEPSS 0.2%CVE-2023-46649MEDIUMRace Condition allows Administrative Access on Organization RepositoriesEPSS 0.2%CVE-2023-6803MEDIUMRace Condition allows Unauthorized Outside CollaboratorEPSS 0.2%CVE-2026-8106MEDIUMReflected HTML injection vulnerability in GitHub Enterprise Server Management Console login page allowed credential theftEPSS 0.2%CVE-2026-77987CRITICALGitHub Enterprise Server notebook viewer vulnerable to Server-side request forgeryEPSS CVE-2026-77912HIGHStored cross-site scripting vulnerability in GitHub Enterprise Server allowed HTML attribute injection via the Markdown rendering pipelineEPSS CVE-2026-75101MEDIUMAuthorization bypass vulnerability in GitHub Enterprise Server allowed reading of private pull request diffs and patches via repository name collisionEPSS