A single git push command could have given an attacker access to millions of private GitHub repositories. Wiz Research found the flaw, and GitHub patched it in under two hours. CVE-2026-3854 is a critical vulnerability in GitHub's internal git proxy, babeld. When processing push options, babeld embedded user-supplied values into an internal header without sanitizing semicolons — the same character used as the field delimiter. Using last-write-wins parsing, an attacker could override security-critical settings with a single push, chaining three overrides to achieve code execution on shared backend storage nodes. GitHub's multi-tenant architecture meant one compromised node exposed every repository stored on it. Wiz reported the flaw on March 4, 2026, and GitHub's security team reproduced it within 40 minutes and deployed a fix in under two hours. GitHub's forensic investigation found no evidence of exploitation. GitHub Enterprise Server patches are available, but according to Wiz, roughly 88% of reachable instances were still unpatched as of April 28th. Sources: https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854 https://github.blog/security/securing-the-git-push-pipeline-responding-to-a-critical-remote-code-execution-vulnerability/ https://www.bleepingcomputer.com/news/security/github-fixes-rce-flaw-that-gave-access-to-millions-of-private-repos/ More on cybersecurity, privacy, scams, and homelab on Hake Hardware. New shorts every weekday.

New VS Code Zero-Day Steals GitHub Tokens in One Click
1.5K views

Microsoft Backs Down on Threats Against Zero-Day Researcher
6.4K views

CIFSwitch Linux Kernel Bug: Any Logged-In User Gets Root
2.3K views

BusPatrol Wants 40,000 School Buses to Be Police Plate Trackers
4.2K views

How the Mirai Trio Avoided Prison (Part 6 of 6)
1.7K views

How the FBI Tracked Down the Mirai Trio (Part 5 of 6)
1.6K views