CVE-2026-3854 — Github Enterprise Server
As of 2026-04-28, CVE-2026-3854 is a HIGH-severity vulnerability in Github Enterprise Server, CVSS v3.1 8.8, EPSS 0.3% (53.5th percentile). Threadlinqs Intelligence links 2 tracked threat campaigns to CVE-2026-3854, most recently “Wiz's Atlas AI Vulnerability Researcher Uncovers Critical GitHub RCE (CVE-2026-3854) and 200+ Unknown OSS Vulnerabilities”.
Last updated: 2026-04-28
What is CVE-2026-3854?
An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to a repository to achieve remote code execution on the instance. During a git push operation, user-supplied push option values were not properly sanitized before being included in internal service headers. Because the internal header format used a delimiter character that could also appear in user input, an attacker could inject additional metadata fields through crafted push option values. This vulnerability was reported via the GitHub Bug Bounty program and has been fixed in GitHub Enterprise Server versions 3.14.25, 3.15.20, 3.16.16, 3.17.13, 3.18.7 and 3.19.4.
The record classifies CVE-2026-3854 under weakness class CWE-77. Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs low-privilege credentials, needs no user interaction, and has high impact on confidentiality, integrity, availability. 1 affected-product entry is recorded, across 1 vendor, listed below. The identifier was first published 186 days ago.
Severity and exploitation probability
- CVSS v3.1 base score
- 8.8 — HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v4.0 base score
- 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS (FIRST)
- 0.3% probability of exploitation in the next 30 days, higher than 53.5% of all scored CVEs
- CISA KEV
- Not listed in the CISA Known Exploited Vulnerabilities catalog
- Published
- 2026-03-10, last modified 2026-04-28
Is CVE-2026-3854 being exploited?
No public exploitation evidence for CVE-2026-3854 is recorded in the sources Threadlinqs tracks — CISA KEV, Exploit-DB, public proof-of-concept repositories and ProjectDiscovery Nuclei — as of 2026-04-28. That is an absence of evidence in those feeds, not a guarantee that the vulnerability is unexploited.
Affected products and versions
- Github: Enterprise Server
How to fix CVE-2026-3854
The record marks a vendor fix as available for CVE-2026-3854. Vendor advisory: https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.4. Apply the vendor fix referenced above to every affected product listed in this record, then confirm the running version against the vendor advisory.
Threat activity tracking CVE-2026-3854
2 tracked threats in the Threadlinqs corpus reference CVE-2026-3854, either in the campaign’s CVE list or as an indicator on the campaign record.
- Wiz's Atlas AI Vulnerability Researcher Uncovers Critical GitHub RCE (CVE-2026-3854) and 200+ Unknown OSS Vulnerabilities — CRITICAL · 2026-07-28
- GitHub.com & GitHub Enterprise Server Pre-Auth RCE via X-Stat Header Field Injection (CVE-2026-3854) — HIGH · 2026-04-29
Sources
Seeded from nvd and not yet processed by the Threadlinqs enrichment pipeline, so blank CVSS, EPSS or KEV fields above mean NOT MEASURED rather than measured-absent.
- docs.github.com
- docs.github.com (release notes)
- docs.github.com (release notes)
- docs.github.com (release notes)
- docs.github.com (release notes)
- docs.github.com (release notes)
- wiz.io
← all vulnerabilities · Markdown version · Threadlinqs Intelligence