CVE Tools

GitHub Enterprise Server

59 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for GitHub Enterprise Server, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.

GitHub Enterprise Server CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
GitHub Enterprise Server CVEs per month
MonthCVEs
2024-102
2024-112
2024-120
2025-011
2025-020
2025-030
2025-043
2025-050
2025-060
2025-071
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-031
2026-040
2026-051
2026-060
2026-070
2026-080
2026-090

Severity

How the 59 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical915%
  • High2136%
  • Medium2847%
  • Low12%

Latest CVEs

The 15 most recently published vulnerabilities affecting GitHub Enterprise Server.

  1. CVE-2026-9312Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to internal services via path traversal in upload endpoint8.2
  2. CVE-2026-3854Remote code execution via git push option injection in GitHub Enterprise Server8.8
  3. CVE-2025-6600GitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Search API4.3
  4. CVE-2025-3246Markdown math block sanitization bypass allows privilege escalation and unauthorized workflow triggers7.6
  5. CVE-2025-3509Pre-Receive Hook Remote Code Execution vulnerability was identified in GitHub Enterprise Server that allowing Privilege Escalation7.2
  6. CVE-2025-3124Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized access to private repository names4.3
  7. CVE-2025-23369Improper Verification of Cryptographic Signature in GitHub Enterprise Server Allows Signature Spoofing by Improper Validation8.8
  8. CVE-2024-10824Authorization Bypass Vulnerability was Identified in GitHub Enterprise Server that Allowed Unauthorized Internal Users to Access Secret Scanning Alert Data6.5
  9. CVE-2024-10007Pre-Receive Hook Path Collision Vulnerability in GitHub Enterprise Server Allowing Privilege Escalation9.1
  10. CVE-2024-9539An information disclosure vulnerability was identified in GitHub Enterprise Server via attacker uploaded asset URL allowing the attacker to retrieve metadata information of a user who clicks on the...4.3
  11. CVE-2024-9487An Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed when the encrypted assertions feature was enabled9.1
  12. CVE-2024-8263An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected all versions of...2.7
  13. CVE-2024-8770A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attackers to steal sensitive user information via social engin...6.1
  14. CVE-2024-6800An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity providers utilizing publicly exposed signed federation m...9.8
  15. CVE-2024-6337Incorrect Authorization allows read access to issues in GitHub Enterprise Server6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store