42
42
55
42
42
60
42
47
42
42
42
55
GitHub Pays $100,000 Bounty for Critical RCE Flaw in Git Push Pipeline
GitHub paid Saif Ghani $100,000 for CVE-2026-3854, a critical unauthenticated RCE in its Git push pipeline allowing command execution on backend infrastructure.
GitHub awarded researcher Saif Ghani $100,000, its largest publicly disclosed bug bounty, for CVE-2026-3854, a critical unauthenticated remote code execution flaw in its Git push processing pipeline. A crafted repository URL could trigger arbitrary command execution on backend infrastructure, threatening source code integrity, repository secrets, and software supply chains. GitHub deployed mitigations and completed a patch rollout through coordinated disclosure before technical details became public.
58
60
42
47
60
55
55
47
60
42
42
60
55
60
55
42
60
55
42
42
55
42
42
57
42
42
42
55