CVE-2026-3854Disclosure(github / enterprise_server)

CRITICALCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 113 mentions and remains active

Immediate actions

  • Patch github enterprise_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to a repository to achieve remote code execution on the instance. During a git push operation, user-supplied push option values were not properly sanitized before being included in internal service headers. Because the internal header format used a delimiter character that could also appear in user input, an attacker could inject additional metadata fields through crafted push option values. This vulnerability was reported via the GitHub Bug Bounty program and has been fixed in GitHub Enterprise Server versions 3.14.25, 3.15.20, 3.16.16, 3.17.13, 3.18.7 and 3.19.4.

9.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_server

Threat summary

  • Active exploitation appears in 36 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 372 mentions across 47 observed days

What's happening

  • Active exploitation reported across 36 signals
  • Exploit tool or code specified in 11 signals
  • PoC mentioned or linked in 31 signals
  • Patch or workaround mentioned in 127 signals
  • Technical details provided in 305 signals
  • Disclosure: 170 classified signals
  • General: 68 classified signals
  • Peaked 43d ago at 113 mentions (2026-04-29); latest day: 1
  • 372 total mentions across 47 days

Affected systems

Vendors
Products
enterprise_server

Deep dive

Activity timeline372 mentions / 47d
0285785113Mentions · 2026-03-12: 1Mentions · 2026-03-16: 1Mentions · 2026-04-28: 80Mentions · 2026-04-29: 113Mentions · 2026-04-30: 37Mentions · 2026-05-01: 8Mentions · 2026-05-02: 3Mentions · 2026-05-03: 7Mentions · 2026-05-04: 4Mentions · 2026-05-05: 7Mentions · 2026-05-06: 5Mentions · 2026-05-07: 3Mentions · 2026-05-08: 4Mentions · 2026-05-09: 1Mentions · 2026-05-10: 1Mentions · 2026-05-11: 3Mentions · 2026-05-12: 2Mentions · 2026-05-13: 3Mentions · 2026-05-15: 4Mentions · 2026-05-16: 1Mentions · 2026-05-18: 2Mentions · 2026-05-20: 18Mentions · 2026-05-21: 2Mentions · 2026-05-22: 2Mentions · 2026-05-23: 1Mentions · 2026-05-25: 3Mentions · 2026-05-26: 3Mentions · 2026-05-27: 4Mentions · 2026-05-28: 5Mentions · 2026-05-29: 4Mentions · 2026-05-31: 2Mentions · 2026-06-03: 1Mentions · 2026-06-06: 8Mentions · 2026-06-08: 1Mentions · 2026-06-11: 2Mentions · 2026-06-16: 6Mentions · 2026-06-24: 2Mentions · 2026-07-02: 1Mentions · 2026-07-21: 1Mentions · 2026-07-22: 6Mentions · 2026-07-23: 4Mentions · 2026-07-30: 1Mentions · 2026-08-04: 1Mentions · 2026-08-07: 1Mentions · 2026-08-10: 1Mentions · 2026-09-14: 1Mentions · 2026-09-17: 1PoC Mentioned / Linked · 2026-04-28: 11PoC Mentioned / Linked · 2026-04-29: 8PoC Mentioned / Linked · 2026-04-30: 3PoC Mentioned / Linked · 2026-05-01: 1PoC Mentioned / Linked · 2026-05-05: 1PoC Mentioned / Linked · 2026-05-06: 1PoC Mentioned / Linked · 2026-05-20: 1PoC Mentioned / Linked · 2026-05-27: 1PoC Mentioned / Linked · 2026-05-28: 1PoC Mentioned / Linked · 2026-05-31: 1PoC Mentioned / Linked · 2026-06-16: 1PoC Mentioned / Linked · 2026-07-22: 1Exploit Tool / Code · 2026-04-28: 5Exploit Tool / Code · 2026-04-29: 1Exploit Tool / Code · 2026-04-30: 1Exploit Tool / Code · 2026-05-06: 1Exploit Tool / Code · 2026-05-20: 1Exploit Tool / Code · 2026-05-28: 1Exploit Tool / Code · 2026-07-22: 1Active Exploitation · 2026-04-28: 8Active Exploitation · 2026-04-29: 5Active Exploitation · 2026-04-30: 4Active Exploitation · 2026-05-03: 2Active Exploitation · 2026-05-04: 1Active Exploitation · 2026-05-06: 2Active Exploitation · 2026-05-20: 5Active Exploitation · 2026-05-21: 1Active Exploitation · 2026-05-22: 1Active Exploitation · 2026-05-26: 2Active Exploitation · 2026-05-27: 2Active Exploitation · 2026-05-31: 1Active Exploitation · 2026-06-03: 1Active Exploitation · 2026-08-04: 1Patch / Workaround · 2026-04-28: 33Patch / Workaround · 2026-04-29: 43Patch / Workaround · 2026-04-30: 13Patch / Workaround · 2026-05-01: 2Patch / Workaround · 2026-05-03: 1Patch / Workaround · 2026-05-05: 3Patch / Workaround · 2026-05-06: 2Patch / Workaround · 2026-05-08: 3Patch / Workaround · 2026-05-10: 1Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-13: 1Patch / Workaround · 2026-05-15: 2Patch / Workaround · 2026-05-20: 4Patch / Workaround · 2026-05-26: 2Patch / Workaround · 2026-05-27: 3Patch / Workaround · 2026-05-28: 2Patch / Workaround · 2026-05-29: 2Patch / Workaround · 2026-06-03: 1Patch / Workaround · 2026-06-06: 1Patch / Workaround · 2026-06-16: 1Patch / Workaround · 2026-07-22: 1Patch / Workaround · 2026-07-30: 1Patch / Workaround · 2026-08-07: 1Patch / Workaround · 2026-09-14: 1Patch / Workaround · 2026-09-17: 1Technical Details · 2026-03-16: 1Technical Details · 2026-04-28: 74Technical Details · 2026-04-29: 96Technical Details · 2026-04-30: 33Technical Details · 2026-05-01: 8Technical Details · 2026-05-02: 2Technical Details · 2026-05-03: 4Technical Details · 2026-05-04: 4Technical Details · 2026-05-05: 4Technical Details · 2026-05-06: 5Technical Details · 2026-05-07: 2Technical Details · 2026-05-08: 4Technical Details · 2026-05-09: 1Technical Details · 2026-05-10: 1Technical Details · 2026-05-11: 2Technical Details · 2026-05-12: 2Technical Details · 2026-05-13: 2Technical Details · 2026-05-15: 4Technical Details · 2026-05-16: 1Technical Details · 2026-05-18: 2Technical Details · 2026-05-20: 11Technical Details · 2026-05-21: 2Technical Details · 2026-05-22: 1Technical Details · 2026-05-23: 1Technical Details · 2026-05-25: 2Technical Details · 2026-05-26: 3Technical Details · 2026-05-27: 2Technical Details · 2026-05-28: 3Technical Details · 2026-05-29: 2Technical Details · 2026-05-31: 1Technical Details · 2026-06-03: 1Technical Details · 2026-06-06: 6Technical Details · 2026-06-08: 1Technical Details · 2026-06-11: 2Technical Details · 2026-06-16: 4Technical Details · 2026-06-24: 1Technical Details · 2026-07-21: 1Technical Details · 2026-07-22: 4Technical Details · 2026-07-23: 2Technical Details · 2026-08-10: 1Technical Details · 2026-09-14: 1Technical Details · 2026-09-17: 103-1204-3005-0405-0805-1205-1805-2305-2806-0606-2407-2308-1009-17
Signal classification8 categories
Disclosure
17045.7%
Patch
8522.8%
General
6818.3%
Active Exploitation
297.8%
PoC
123.2%
Exploit
61.6%
Referenced assets141 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-121
Disclosure1
2026-03-161
General1
2026-04-2880
Active Exploitation8Disclosure46Discloure1Exploit3False Positive1General5Patch14PoC2
2026-04-29113
Active Exploitation3Disclosure57Exploit3General13Patch33PoC4
2026-04-3037
Active Exploitation3Disclosure15General5Patch12PoC2
2026-05-018
Disclosure6Patch2
2026-05-023
Disclosure2General1
2026-05-037
Active Exploitation1Disclosure2General3Patch1
2026-05-044
Active Exploitation1Disclosure2General1
2026-05-057
Disclosure4General2Patch1
2026-05-065
Active Exploitation1Disclosure2Patch1PoC1
2026-05-073
Disclosure1General2
2026-05-084
Disclosure1Patch3
2026-05-091
Disclosure1
2026-05-101
Disclosure1
2026-05-113
Disclosure1General1Patch1
2026-05-122
Disclosure1Patch1
2026-05-133
Disclosure1General1Patch1
2026-05-154
Disclosure2General1Patch1
2026-05-161
Disclosure1
2026-05-182
Disclosure2
2026-05-2018
Active Exploitation4Disclosure1General9Patch3PoC1
2026-05-212
Active Exploitation1Disclosure1
2026-05-222
Active Exploitation1Disclosure1
2026-05-231
General1
2026-05-253
Disclosure1General2
2026-05-263
Active Exploitation1General1Patch1
2026-05-274
Active Exploitation2General1Patch1
2026-05-285
Disclosure1General2Patch1PoC1
2026-05-294
Disclosure1General1Patch2
2026-05-312
Active Exploitation1General1
2026-06-031
Active Exploitation1
2026-06-068
Disclosure4General3Patch1
2026-06-081
Disclosure1
2026-06-112
Disclosure1General1
2026-06-166
Disclosure2General3Patch1
2026-06-242
Disclosure1General1
2026-07-021
General1
2026-07-211
Disclosure1
2026-07-226
Disclosure2General3PoC1
2026-07-234
Disclosure2General2
2026-07-301
Patch1
2026-08-041
Active Exploitation1
2026-08-071
Patch1
2026-08-101
Disclosure1
2026-09-141
Patch1
2026-09-171
Patch1
Full discourse20 posts
  • sagitz@sagitz_
    Active Exploitation

    We achieved Remote Code Execution on GitHub - and got access to millions of repositories belonging to other users and organizations 🤯 All it took was a single `git push` Here's how we did it (CVE-2026-3854) 🧵⬇️ https://t.co/CrnBRDoxL3

    Post summary

    The author claims to have exploited CVE-2026-3854 on GitHub with a single git push, providing a link to further details and indicating the vulnerability’s active exploitation.

    1801.3K2868.4K3.6K1.5M
    8.2K followersView on X
  • International Cyber Digest@IntCyberDigest
    Active Exploitation

    ‼️🚨 BREAKING: Wiz got access to millions of GitHub repositories across users and organizations using one git push. CVE-2026-3854: git push -o options injected into an internal header split by semicolons, parsed last-write-wins. GitHub patched production in 6 hours. https://t.co/aSH2UCsYmc

    Post summary

    The text reports that CVE‑2026‑3854 was actively exploited by Wiz via a single git push, provides technical details of the flaw, and notes that GitHub issued a patch within six hours.

    27237381.6K442226.7K
    184.6K followersView on X
  • Fazt@FaztTech
    Active Exploitation

    Las últimas semanas en ciberseguridad están siendo brutales: → GitHub: 3,800 repos internos filtrados (20 mayo) → GitHub: CVE-2026-3854, RCE con un solo git push → npm: 42 paquetes de Tanstack envenenados (12M descargas/semana) → Microsoft: 138 vulnerabilidades parcheadas este mes → Exchange (Microsoft): CVE-2026-42897, JS arbitrario abriendo un correo Y Hoy le encuentran un 0 day a Nginx y están investigando una versión maliciosa de NxConsole Y lo más loco: el mismo grupo (TeamPCP) está detrás de los ataques a npm Y a GitHub. No son incidentes aislados, es una campaña coordinada contra la infraestructura que TODOS usamos. En 2025 se publicaron casi medio millón de paquetes maliciosos. Y seguimos instalando a ciegas. Y de momento no parece que vaya a terminar estos problemas

    Post summary

    The post reports multiple newly discovered vulnerabilities—including a 0‑day in Nginx and RCE on GitHub—while highlighting active exploitation by a threat group (TeamPCP) and noting that vendors are patching related flaws.

    24227141.4K32673.4K
    59.1K followersView on X
  • sagitz@sagitz_
    General

    This is the bug: https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854

    Post summary

    The snippet references a blog post about CVE‑2026‑3854 but provides no explicit technical, exploit, or mitigation details.

    1273776155183.5K
    11.5K followersView on X
  • Co11ateral@co11ateral
    Disclosure

    CVE-2026-3854 RCE
 git push -o allows users to send arbitrary strings to the server. GitHub embeds them directly into an internal header without sanitizing the delimiter.
 A semicolon in the push option makes it possible to override security-critical fields.
 Results: sandbox escape leading to RCE as the git service user in GHES https://github.blog/security/securing-the-git-push-pipeline-responding-to-a-critical-remote-code-execution-vulnerability/

    Post summary

    GitHub discloses CVE‑2026‑3854, describing an RCE via unsanitized git push options and linking to a vendor advisory detailing the patch.

    32602287215.3K
    8.4K followersView on X
  • The Hacker News@TheHackersNews
    Disclosure

    🔥 GitHub RCE via single git push! CVE-2026-3854: Unsanitized push options let attackers run commands on backend servers, bypassing sandboxing (cross-tenant risk). 🔗 Learn how header injection led to full compromise → https://thehackernews.com/2026/04/researchers-discover-critical-github.html Patched within hours.

    Post summary

    GitHub disclosed a critical RCE flaw (CVE‑2026‑3854) caused by unsanitized push options; the vulnerability was patched quickly and no active exploitation or exploit code was reported.

    85851623423.5K
    1.8M followersView on X
  • Cyber Security News@The_Cyber_News
    Disclosure

    ⚠️Critical GitHub[.]com and Enterprise Server RCE Vulnerability Enables Full Server Compromise Source: https://cybersecuritynews.com/github-com-and-enterprise-server-rce/ A critical remote code execution (RCE) vulnerability tracked as CVE-2026-3854 in GitHub's internal git infrastructure that could have allowed any authenticated user to compromise backend servers, access millions of private repositories, and, in the case of GitHub Enterprise Server (GHES), achieve full server takeover. CVE-2026-3854 stems from an improper neutralization of special elements (CWE-77) in how GitHub's internal babeld git proxy handled user-supplied push option values. The vulnerability arises because babeld copied these values verbatim into a semicolon-delimited internal X-Stat header without sanitizing the semicolon character the same character used as a field delimiter. #cybersecuritynews #GitHub

    Post summary

    The post announces CVE‑2026‑3854, a critical RCE in GitHub’s internal git infrastructure, detailing the flaw’s technical aspects but offering no PoC, exploit code, patch, or evidence of active attacks.

    154421603514.1K
    67.1K followersView on X
  • RootMonsteR@RootMonsteR
    Active Exploitation

    no evidence of impact but actively monitoring for follow-on activity is just corporate speak for we don't know what they took yet. three weeks after CVE-2026-3854 let any authenticated user RCE the platform and read millions of private repos. how many of these before it stops being framed as an isolated incident?

    Post summary

    The text reports that CVE-2026-3854 is being actively exploited in the wild, allowing authenticated users to perform remote code execution and access private repositories.

    41921775077.5K
    788 followersView on X
  • 7h3h4ckv157@7h3h4ckv157
    Disclosure

    Wiz Research uncovers Remote Code Execution in GitHub[.]com and GitHub Enterprise Server (CVE-2026-3854) Author: Sagi Tzadik Read: https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854 https://t.co/bhrLctbh9W

    Post summary

    Wiz Research announces a new Remote Code Execution vulnerability (CVE‑2026‑3854) affecting GitHub.com and GitHub Enterprise Server, with details posted on its blog.

    011143123.1K
    56.8K followersView on X
  • Helixar AI@Helixar_ai
    Disclosure

    Critical GitHub RCE Flaw (CVE-2026-3854) Threatens AI Supply Chains. Researchers discovered a command injection vulnerability in GitHub's core infrastructure, creating a significant risk for autonomous development agents and the integrity of AI model repositories. https://helixar.ai/press/github-rce-cve-2026-3854-agentic-risk/

    Post summary

    The release announces a critical GitHub command injection (CVE‑2026‑3854) that could allow remote code execution in the platform's core infrastructure.

    2500260345
    106 followersView on X
  • xjdr@_xjdr
    General

    ooooffff, this is a particularly scary class of bug (especially given recent events) but hats off to github for the detailed report https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854

    Post summary

    The tweet merely references a detailed blog report on CVE-2026-3854 without providing concrete evidence of a PoC, exploit, patch, or technical details.

    1003363.8K
    29.3K followersView on X
  • Critical Thinking - Bug Bounty Podcast@ctbbpodcast
    Disclosure

    CVE-2026-3854 was a GitHub RCE fired with `git push -o`, the standard flag for passing arbitrary strings to the server, and those strings landed inside the internal header GitHub's own backend reads to decide what you are allowed to do, any authenticated user with push access to a repo could send it. The header is `X-Stat`, built by babeld out of the security policies gitauth hands back for your session, then parsed downstream by gitrpcd, which authenticates nothing itself and treats every field in it as authoritative. Fields are semicolon-delimited key=value pairs and duplicates resolve last-write-wins. babeld copied push option values in as `push_option_0` and friends without stripping semicolons, so a semicolon broke out of its field and everything behind it parsed as fresh fields, sitting later in the header than the legitimate ones. Three of those fields reach the pre-receive hook binary, `rails_env` picks between its two execution paths, sandboxed on production and running directly as the git user on anything else, `custom_hooks_dir` sets the base directory for hook script lookup, `repo_pre_receive_hooks` carries JSON hook definitions, and a script field holding traversal resolves against that base directory to an arbitrary binary, which the unsandboxed path then executes. On GitHub the same chain went through as an ordinary push and nothing ran. Injecting `user_operator_mode=bool:true` for debug output showed the custom hooks step missing from the list, and the binary held a boolean marking enterprise mode, false there and injectable like everything else. Setting it landed execution as the git user on a shared storage node holding other organisations' repositories.

    Post summary

    The post discloses a GitHub RCE (CVE‑2026‑3854) triggered via the ‘git push -o’ flag, detailing how manipulated X‑Stat headers lead to unsandboxed pre‑receive hook execution and arbitrary binary runs.

    00024143.2K
    27.3K followersView on X
  • Cyberkid@Anastasis_King
    Disclosure

    🔥 GitHub RCE via single git push! CVE-2026-3854: Unsanitized push options let attackers run commands on backend servers, bypassing sandboxing (cross-tenant risk). 🔗 Learn how header injection led to full compromise → https://thehackernews.com/2026/04/researchers-discover-critical-github.html?m=1 https://t.co/1zDm9kQxLU

    Post summary

    The post announces CVE-2026-3854, describing how unsanitized git push options on GitHub allow command execution on backend servers, creating a cross‑tenant risk.

    050218973
    10.6K followersView on X
  • ZeroDayDev@ZeroDayDevApp
    Disclosure

    GitHub's recent CVE-2026-3854 allows any authenticated user to execute code remotely with a single 'git push'. This RCE vulnerability emphasizes the critical need for tighter access controls—one misconfigured repo could turn into a nightmare for teams. https://thehackernews.com/2026/04/researchers-discover-critical-github.html

    Post summary

    GitHub disclosed CVE-2026-3854, an RCE that permits any authenticated user to execute code via a single git push, highlighting the importance of stricter access controls.

    1400190304
    97 followersView on X
  • Densel@luckyhacker43
    Disclosure

    [CVE-2026-3854] RCE on GitHub via Single Git Push 💀 Securing GitHub: Wiz Research uncovers Remote Code Execution in http://GitHub.com and GitHub Enterprise Server by Sagi Tzadik 🤯🔥 🔗 https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854 🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-3854 🔗 https://t.me/luckyhacker43 https://t.co/ie5ogHan89

    Post summary

    A new vulnerability, CVE‑2026‑3854, is disclosed as a Remote Code Execution flaw triggered by a single Git push on GitHub and GitHub Enterprise Server, with links to an informational blog and NVD entry but no PoC, exploit code, or patch details.

    010207772
    2.7K followersView on X
  • Yang ⛧🤍 (UwU Underground)@ghostofyvng
    General

    "We heard you. And we agree. The only way to keep your code safe is not on our servers." https://www.wiz.io/blog/teampcp-attack-kics-github-action https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854 https://www.wiz.io/blog/mini-shai-hulud-teampcp-hits-antv-supply-chain Ad Infinitum.

    Post summary

    The snippet references CVE‑2026‑3854 only via a link, with no further technical details, PoC, exploit, or patch information provided.

    1112301.5K
    542 followersView on X
  • Cert AgID@AgidCert
    Disclosure

    GitHub e GitHub Enterprise Server: vulnerabilità RCE CVE-2026-3854 🔬Lo sfruttamento permette RCE lato server durante push, con output restituito al client, confermando l’esecuzione nel contesto dell’utente git. ℹ️ Ulteriori informazioni 👇 🔗 https://cert-agid.gov.it/news/github-e-github-enterprise-server-vulnerabilita-rce-cve-2026-3854/ https://t.co/DnfzgbYsYc

    Post summary

    The post announces a server‑side RCE (CVE‑2026‑3854) affecting GitHub and GitHub Enterprise Server, exploitable during push operations with output returned to the client, confirming execution as the git user.

    151821.4K
    4.1K followersView on X
  • divyansh tiwari@DivyanshT91162
    Active Exploitation

    Someone just pulled off Remote Code Execution on GitHub… and it exposed access to millions of private repositories. No complex exploit chain. No zero-day hunting spree. Just one git push. Yeah. That’s it. Tracked as CVE-2026-3854 — and it’s way more insane than it sounds. Here’s how it actually went down 🧵👇

    Post summary

    The post reports that CVE‑2026‑3854 has been actively exploited on GitHub, exposing millions of private repositories, with no PoC or mitigation details provided.

    1301021.2K
    8.9K followersView on X
  • 中島佑允(YusukeNakajima)@nakajimeeee
    Disclosure

    【脆弱性/開発基盤セキュリティ】git push一発でGitHubサーバーを掌握——CVE-2026-3854が突いた内部プロトコルの盲点 Wizの研究者がhttp://GitHub.comおよびGitHub Enterprise Server全バージョンに影響するリモートコード実行脆弱性(CVE-2026-3854、CVSS 8.7)を発見した。リポジトリへのプッシュ権限さえあれば、特殊なgit pushオプションを一度送信するだけでサーバー上での任意コード実行が可能となる。 根本原因は内部ヘッダー「X-Stat」の設計にある。gitのプッシュオプション値がセミコロン区切りで内部メタデータに展開される際、ユーザー入力が無検証で挿入される。攻撃者はこれを利用してRailsの実行環境変数・カスタムフックディレクトリ・フックエントリを連鎖的に上書きし、サンドボックスを突破して任意コマンドをgitユーザー権限で実行できる。 特に深刻なのはhttp://GitHub.comにおける影響範囲だ。マルチテナント構成のバックエンドでコード実行を達成した場合、同一ストレージノード上の他組織のリポジトリを横断的に閲覧できる状態となる。公開時点でEnterprise Serverの約88%が脆弱だったと報告されている。GitHubは報告受領から2時間以内にhttp://GitHub.comへの修正をデプロイし、Enterprise Serverの各バージョンにもパッチを提供済みである。悪意ある利用の証拠は現時点で確認されていないが、Enterprise Serverを自己ホストする組織は即時のアップデート適用が必須だ。 https://thehackernews.com/2026/04/researchers-discover-critical-github.html

    Post summary

    Researchers disclosed CVE‑2026‑3854, a remote code execution flaw in GitHub’s X‑Stat header, and GitHub quickly patched the issue; no active exploitation has been reported.

    010951.1K
    2.9K followersView on X
  • Cyber_OSINT@Cyber_O51NT
    Disclosure

    Wiz Research disclosed a critical CVE-2026-3854 flaw in GitHub’s internal git infrastructure, enabling remote code execution on http://GitHub.com and GitHub Enterprise Server. https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854

    Post summary

    Wiz Research announced the discovery of a critical remote‑code‑execution vulnerability (CVE‑2026‑3854) affecting GitHub’s internal git infrastructure, without providing a PoC or evidence of active exploitation.

    040911.2K
    22.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgithubenterprise_server---

Explore more