github has 9 CVEs on record between 2024 and 2026. Disclosure cadence is accelerating: 6 in the last 90 days against 2 in the 90 before. The busiest recent month was September 2026 with 3. The median CVSS is 7.5 (high), with 1 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-918 (3). Most affected products: enterprise_server (4), github.com/github/github-mcp-server (2), cmark-gfm (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 6 prev 2
Products
- enterprise_server 4
- github.com/github/github-mcp-server 2
- cmark-gfm 1
- com.github.jknack:handlebars 1
- com.github.jknack:handlebars-springmvc 1
Worst active — by depth score
CVE-2024-22051Critical· 9.8CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability54CVE-2026-76851High· 8.8A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance49CVE-2026-9312High· 8.2A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload…46CVE-2026-19118High· 7.5A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution41CVE-2026-18730High· 7.4A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send crafted outbound requests to an attacker-controlled host41
github vulnerabilities
CVEs affecting github, newest first. Open any entry for full detail, references, and exploit status.
9 CVEsRSS
CVE-2026-18730High· 7.4A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send crafted outbound requests to an attacker-controlled host
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send crafted outbound requests to an attacker-controlled host. An unauthent…
CVE-2026-76851High· 8.8A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance. Insufficient network isolation allowed malicious pre-receive hook code to impersonate an in…
CVE-2026-19118High· 7.5A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution
A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution. Exploitation required an authenticated user with write access to a repository and precise timing of c…
CVE-2026-63490High· 7.5Handlebars.java provides logic-less and semantic Mustache templates with Java
Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader w…
CVE-2026-47427High· 7.5GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler
GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler
CVE-2026-48529Medium· 6.0GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion
GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion
CVE-2026-55760High· 7.5handlebars.java FileTemplateLoader Path Traversal
handlebars.java FileTemplateLoader Path Traversal
CVE-2026-9312High· 8.2A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload…
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload…
CVE-2024-22051Critical· 9.8CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability
CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information lea…