logo

CVE-2026-3854 Exposes a Critical Weak Point in GitHub’s Git Push Pipeline

ID: c6741edf-0a8c-527e-9c52-37f91551a3aa

STIX ID: report--c6741edf-0a8c-527e-9c52-37f91551a3aa

Feed Name: SOCRadar Blog

Threat Score
80/100

Date Published: 2026-04-29

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

This report details CVE-2026-3854, a critical remote code execution flaw in GitHub's git push pipeline that allowed crafted git push options to inject unsanitized metadata and potentially execute commands on servers; GitHub issued patches for supported Enterprise Server releases, reported no evidence of in-the-wild exploitation or customer data compromise, and recommends immediate upgrades and review of recent push activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.