GitHub has 12 CVEs on record between 2024 and 2026. Disclosure cadence is accelerating: 8 in the last 90 days against 3 in the 90 before. The busiest recent month was September 2026 with 6. The median CVSS is 7.5 (high), with 2 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-918 (4). Most affected products: enterprise_server (4), Enterprise Server (3), github.com/github/github-mcp-server (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 8 prev 3
Products
- enterprise_server 4
- Enterprise Server 3
- github.com/github/github-mcp-server 2
- cmark-gfm 1
- com.github.jknack:handlebars 1
- com.github.jknack:handlebars-springmvc 1
Worst active — by depth score
CVE-2024-22051Critical· 9.8CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability54CVE-2026-77987Critical· 9.3A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server51CVE-2026-76851High· 8.8A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance49CVE-2026-9312High· 8.2A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload…46CVE-2026-77912High· 7.4A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because the Markdown rendering pipeline rewrot…41
GitHub vulnerabilities
CVEs affecting GitHub, newest first. Open any entry for full detail, references, and exploit status.
12 CVEsRSS
CVE-2026-77987Critical· 9.3A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server
A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the port, allowing reques…
CVE-2026-75101Medium· 6.0An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch of pull requests in private repositories without authorization
An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch of pull requests in private repositories without authorization. Access tok…
CVE-2026-77912High· 7.4A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because the Markdown rendering pipeline rewrot…
A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because the Markdown rendering pipeline rewrot…
CVE-2026-18730High· 7.4A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send crafted outbound requests to an attacker-controlled host
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send crafted outbound requests to an attacker-controlled host. An unauthent…
CVE-2026-76851High· 8.8A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance. Insufficient network isolation allowed malicious pre-receive hook code to impersonate an in…
CVE-2026-19118High· 7.5A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution
A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution. Exploitation required an authenticated user with write access to a repository and precise timing of c…
CVE-2026-63490High· 7.5Handlebars.java provides logic-less and semantic Mustache templates with Java
Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader w…
CVE-2026-47427High· 7.5GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler
GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler
CVE-2026-48529Medium· 6.0GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion
GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion
CVE-2026-55760High· 7.5handlebars.java FileTemplateLoader Path Traversal
handlebars.java FileTemplateLoader Path Traversal
CVE-2026-9312High· 8.2A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload…
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload…
CVE-2024-22051Critical· 9.8CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability
CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information lea…