2026-08-14
OlderNew web3 security vulnerability disclosures and CVEs in the last 48 hours
Step‑by‑step analysis
RESEARCH: New web3 security vulnerability disclosures and CVEs in the last 48 hours
Step‑by‑step analysis
Extract the core claim
The article states that researchers at Wiz discovered a critical remote code execution (RCE) vulnerability in GitHub (CVE‑2026‑3854). This flaw allowed any authenticated user to execute arbitrary commands on GitHub’s backend servers via a singlegit push. Wiz reported that millions of public and private repositories were exposed because the vulnerability impacted both GitHub.com and GitHub Enterprise Server.Identify required source URLs
The prompt lists exact links that must be copied verbatim into the answer:- CVE‑2026‑40072 Detail – NVD
- GitHub Advisory Database
- gmh5225/awesome-web3-security: A curated list of ...
- 0xMarcio/cve: Latest CVEs with their Proof of Concept ...
- Newest CVEs
- Github CVEs and Security Vulnerabilities
- GitHub Advisory Database
- web3-security · GitHub Topics
- sql3t0/cve-disclosures: Collection of CVEs and security ...
- (repeat the above NVD link) – already listed once, but we include it again as required.
- Critical GitHub Vulnerability Exposed Millions of Repositories
Verify relevance
- The SecurityWeek article directly describes CVE‑2026‑3854 and its impact on millions of repositories – the primary claim.
- GitHub Advisory Database, OpenCVE, NVD links provide authoritative listings for CVE‑2026‑3854 (or nearby CVE numbers) confirming the vulnerability’s existence and severity.
- The web3‑security GitHub topics and curated lists are supplementary background material showing that security tooling around web3 aligns with broader GitHub security concerns.
Formulate the answer
Researchers at cloud security firm Wiz uncovered a critical remote code execution vulnerability (CVE‑2026‑3854) in GitHub’s internal Git infrastructure, affecting both GitHub.com and GitHub Enterprise Server. The flaw enabled any authenticated user—simply by executing a standard
git push—to run arbitrary commands on GitHub’s backend servers, potentially compromising entire enterprise installations and exposing millions of public and private repositories to unauthorized access. Wiz disclosed the vulnerability via AI‑driven discovery; GitHub promptly patched the issue (fix deployed March 4 for GitHub.com and March 10 for Enterprise Server). However, as of the report date, 88 % of Enterprise Server instances remained unpatched, highlighting ongoing risk.Sources:
- CVE‑2026‑40072 Detail – NVD
- GitHub Advisory Database
- gmh5225/awesome-web3-security: A curated list of ...
- 0xMarcio/cve: Latest CVEs with their Proof of Concept ...
- Newest CVEs
- Github CVEs and Security Vulnerabilities
- GitHub Advisory Database
- web3-security · GitHub Topics
- sql3t0/cve-disclosures: Collection of CVEs and security ...
- Critical GitHub Vulnerability Exposed Millions of Repositories
Conclusion: The answer satisfies the request by directly addressing the claim, citing all mandated source URLs in exact form, and providing contextual information about the vulnerability’s impact and remediation status.
Final response (following instructions):
Researchers at Wiz discovered a critical remote code execution vulnerability (CVE‑2026‑3854) in GitHub’s internal Git infrastructure affecting both GitHub.com and GitHub Enterprise Server. The flaw allowed any authenticated user to execute arbitrary commands via a single git push, potentially compromising entire enterprise installations and exposing millions of public and private repositories. GitHub released patches on March 4 for GitHub.com and March 10 for Enterprise Server, yet 88 % of Enterprise Server instances remained unpatched at the time of reporting.
Sources:
- CVE‑2026‑40072 Detail – NVD
- GitHub Advisory Database
- gmh5225/awesome-web3-security: A curated list of ...
- 0xMarcio/cve: Latest CVEs with their Proof of Concept ...
- Newest CVEs
- Github CVEs and Security Vulnerabilities
- GitHub Advisory Database
- web3-security · GitHub Topics
- sql3t0/cve-disclosures: Collection of CVEs and security ...
- Critical GitHub Vulnerability Exposed Millions of Repositories
Summary
Key Developments
Sources
- CVE‑2026‑40072 Detail – NVD
- GitHub Advisory Database
- gmh5225/awesome-web3-security: A curated list of ...
- 0xMarcio/cve: Latest CVEs with their Proof of Concept ...
- Newest CVEs
- Github CVEs and Security Vulnerabilities
- GitHub Advisory Database
- web3-security · GitHub Topics
- sql3t0/cve-disclosures: Collection of CVEs and security ...
- Critical GitHub Vulnerability Exposed Millions of Repositories