logo

GitHub Fixes Critical RCE Bug CVE-2026-3854 Within Hours of Discovery

ID: 92312ca5-80e0-53f9-9e8b-47902e5ffa6b

STIX ID: report--92312ca5-80e0-53f9-9e8b-47902e5ffa6b

Feed Name: The Cyber Express

Threat Score
70/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Ashish Khaitan

...
...

GitHub disclosed CVE-2026-3854, a critical RCE in how user-supplied git push options were sanitized that allowed attackers to inject fields into internal headers (via semicolons) and execute arbitrary commands; GitHub patched cloud services the same day and released Enterprise Server updates, found no evidence of exploitation, and advised admins to upgrade immediately and review audit logs for suspicious push options.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.