5 ms·
GitHub RCE Vulnerability: CVE-2026-3854 Breakdown
- latchkey 5mo agoPeople keep wanting to replace GitHub, but with what? If GH is getting RCE's this late in the game who wants to take the chance something else won't?
- gtech1 5mo agoGitLab ?
- latchkey 5mo agoThe people who suggest gitlab, haven't used it. But I guess I could be tempted to try again... https://status.gitlab.com/pages/history/5b36dc6502d06804c08349f7 https://status.gitlab.com/pages/history/5b36dc6502d06804c083...
- capitalhilbilly 5mo agoIf you could only choose from github, gitlab and atlassan then I suppose.. But really anything newer that stays in existance has to be focused on quality from early enough to not be defined by path dependence problems and bad choices like those 3.
- latchkey 5mo agoGiven that github is imploding under a lot of load, everyone leaving github for something else, actually makes github better.
- gtech1 5mo agoAh, you assumed I meant SaaS GitLab. I meant the self-hosted version. I would never host our source code on a remote service.
- latchkey 5mo agoWhy not?
- gtech1 5mo agoBecause I don't trust someone else to not train or steal our source code, or, even legally, introduce some silly cause after we are invested/locked into their infra, that allows them to do whatever with our property. And on equal footing, I trust our security more than theirs. Case in point.
- himata4113 5mo agoMe and my friends call it CveLab because there was a time where there was a critical security update every week or multiple times a week.
- chucky_z 5mo ago.... git? replace it with git. if you want a whole ui you can use something like forgejo which has far fewer features likely leading to less issues.
- latchkey 5mo agoi want what github offers.
- heliumtera 5mo agoEnjoy your experience, there will certainly be no end to it.
- latchkey 5mo agoI've had my account since 2008. ¯\_(ツ)_/¯ updated: changed the date to 2008. my account shows 2001, but that's probably from projects I moved over... proof: https://github.com/lookfirst https://github.com/lookfirst
- sitzkrieg 5mo agoi just deleted my account of 2008. github sucks
- necubi 5mo agoGitHub launched in 2008, so that seems unlikely?
- seanclayton 5mo agoJust be careful your patronage doesn't lead to a sunk cost fallacy---a middle manager might just be betting on it
- latchkey 5mo agoI have no ingrained loyalty, I just haven't found something better.
- Caligatio 5mo agoI am personally now drawing a clear delineation between projects for my internal consumption (e.g. ansible scripts) and projects that have potential use for the general populace. For the prior, I now host a private Forgejo instance. For the latter, I'll put it on GitHub but mirror it to my Forgejo instance. I was pleasantly shocked that Forgejo is literally a single binary with a relatively easy config. All my internal services reference my Forgejo instance so, if I need to bail on GitHub, it's low friction for me.
- skrrtww 5mo agoA "reasonable" answer is probably a primary self-hosted Forgejo instance as the canonical forge, while using GitHub as a mirror solely to take advantage of its free CI, while that lasts, while hosting secrets with a dedicated secret-hosting provider (I don't know what the provider du jour for this is these days).
- latchkey 5mo agoReplace a whole 24/7 team of devops people with myself? As much as I'd like to believe that I'm worthy, I'm not.
- skrrtww 5mo agoIf the primary forge's only job is to host the actual Git infrastructure (the code, the MRs, the issues, maybe a wiki), it's a lot more simple than GitHub, and probably more within the scope of what people can reasonably administer themselves.
- latchkey 5mo agoI hosted the first "java.apache.org". I was an early employee at CollabNet, and in the first discussions around starting subversion. I worked on Cloud Foundry. This stuff isn't easy and I'm more than happy letting someone else do it at the expense of some downtime.
- slopinthebag 5mo ago24/7 devops team for a forgejo instance? Come on mate...
- latchkey 5mo ago24/7 devops team for github? Come on mate...
- slopinthebag 5mo ago
- TZubiri 5mo agojust git
- crimsonnoodle58 5mo agoSelf hosted gitlab behind a VPN. The all-in-docker image and a couple of gitlab runners is all small to medium sized teams need. (Don't overcomplicate it with the kubernetes version unless you really need it)
- asa977 5mo agoWe moved from github to a self-hosted forgejo instance about 6 months ago, works like a charm. Still can't belive how snappy forgejo is / laggy github has become
- latchkey 5mo agoIs it public or locked down? https://news.ycombinator.com/item?id=47941590 https://news.ycombinator.com/item?id=47941590
- trashb 5mo agoNo worries Thomas Dohmke has you covered with his new project. https://news.ycombinator.com/item?id=46961345 https://news.ycombinator.com/item?id=46961345 https://news.ycombinator.com/item?id=47712656 https://news.ycombinator.com/item?id=47712656
- willworktill4pm 5mo agoGitHub case will be thought in schools how to screw up almost monopolistic position in the market in couple years. This is beyond bonkers.
- bananapub 5mo ago> April 28, 2026 > GitHub Enterprise Server customers should upgrade immediately - at the time of this writing, our data indicates that 88% of instances are still vulnerable > Upgrade to GHES version 3.19.3 or later https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.3 https://docs.github.com/en/enterprise-server@3.19/admin/rele... : > Enterprise Server 3.19.3 - March 10, 2026 88% of on-prem customers haven't applied a critical security fix from 7 weeks ago, that seems ... bad.
- pixl97 5mo agoQuestion is how fragile the upgrade process is in large installations. In other enterprise software messing around with large amounts of data I've seen the smallest things break the install and leaving the OPs team rolling back. Was like SharePoint in the past, you were rolling a dice when upgrading it.
- chucky_z 5mo agoIt's incredibly fragile. It breaks a vast majority of the time and takes multiple rounds of support on-call to upgrade typically.
- formerly_proven 5mo agoUnsurprising for a fourth tier on-prem created by cutting a continuously deployed application into releases.
- jamesfinlayson 5mo agoThe GitHub blog had an article saying that all patches must pass for github.com before merge but the GitHub Enterprise tests have a three day window to be rectified.
- bombcar 5mo agoIf you're in the enterprise you can update something outside of the normal schedule and guarantee blow up everything (and be blamed) or you can stick with the schedule and hope for the best. Guess which is usually picked ...
- WASDx 5mo agoI was impressed enough by AI finding vulnerabilities in source code, but doing it in binary executables is just amazing. This has so much potential, good and bad. And yet another lesson to not treat data as instructions. Sanitize all user input!
- avaer 5mo agoTransformers were literally designed for translation. As we have known for a while, they ended up being really good at translating source to source or text to source. It shouldn't be too surprising they are also really good at understanding the asm version too. Doesn't make it any less impressive, but maybe less surprising.
- jcims 5mo agoAnyone in here work at Wiz? Seem like they do pretty good work. Tool itself has survived extreme growth/feature bloat and still does pretty well. Security team has found some really cool stuff.
- az226 5mo agoLots of Unit 8200 peeps.
- rvnx 5mo agoInteresting how people sourcing these softwares say China = bad, but Israel = good. "Trusted by more than 50% of Fortune 100 companies". You choose to give your most precious data and the keys of infrastructure whose job was to steal information and with people that are still NSA/8200 employees. Don't be surprised if one day they are compelled to share data or find dirt on people (they protect one well known LLM company). It doesn't mean they are doing it, but clearly the incentive for it exists, + you are exposed to both US and IL jurisdictions risk.
- samlinnfer 5mo ago>China bad, Israel good They're just aligning themselves with US foreign policy.
- SlightlyLeftPad 5mo agoThe founder came from Unit 8200, an Israeli cyberwarfare operation, that’s where the alignment comes from, not simply US foreign policy which is coincidental.
- jospeh554 5mo agoI'm not there, but we use it at our place. It triggers on entirely innocent things I do. And yet when I do something a bit dodgy (like query a DC with a cli, and reset credentials) it's silent...
- 5mo ago
- halger 5mo agoWoah I wonder if they can tell if this has been exploited or not
- semiquaver 5mo agoMy read is that this vulnerability is exploitable by an anonymous user. They absolutely have HTTP/gitprotocol logs that would indicate whether this was exploited but if it was, they won’t have logging about what actually got accessed and who did it, since the exploit was capable of standalone execution on the git servers, which would by definition be capable of evading any logging.
- formerly_proven 5mo agoThis is just such an amateur hour vulnerability. Gluing strings together with no regard to what might be in them and then parsing them later... edit: I didn't mean it as a put-down of either the article or how they found the vulnerability, but it wasn't a constructive comment either way.
- dang 5mo agoIt's good to add information about what the vulnerability actually was, but please don't do it in the key of putdown. We're trying for something else here. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- jfkimmes 5mo agoThey hint at their AI-augmented reversing methodology, which demonstrates one of the core strengths of current LLM agents. These models, trained extensively on code, can immensely speed up the process of understanding complex system internals. Security research historically has two difficult components that build on one another: 1. Understanding complex system internals: uncovering the inner workings hidden by abstractions or interfaces 2. Finding vulnerabilities in these uncovered mechanisms Sometimes both steps are equally hard. But often, finding the vulnerability is trivial once the real mechanisms are uncovered, rather than relying on assumptions about inner workings. CVE-2026-3854 is a case where the vulnerability is not plainly obvious after understanding the internals. Still, I am confident that this command injection would have been found quickly had it been exposed to a more traditional or accessible attack surface.
- sylware 5mo agoYep, there was a signal to help reverse engineer c++, as it could have been good at helping c++ mass porting to plain and simple C. But recently this signal got somewhat scrambled, or being sabotage by c++ fan boys (those coding AIs would help getting rid of dev/vendor lock-ing using c++ syntax complexity)
- huflungdung 5mo ago[dead]
- Neteam 5mo ago[dead]
- angry_octet 5mo agoAnother tour de force from Wiz, and a watershed moment in AI tooling enabling RE and compromise discovery.
- avaer 5mo agoIt throws a wrench into the argument of not publishing your source because AI will more easily compromise the code. Another data point against doing security through obscurity.
- samlinnfer 5mo agoWithout the enterprise binaries, there is zero chance of finding this. Another win for obscurity.
- jeremie_strand 5mo ago[dead]
- saghm 5mo ago> When babeld forwards a push request, one of the internal requests includes push options in the X-Stat header. Git push options are arbitrary strings that users can pass with git push -o. They are a standard git protocol feature, intended for server-side hints. babeld encodes them as numbered fields - push_option_0, push_option_1, and so on - alongside a push_option_count. > babeld copies git push option values directly into the X-Stat header - without sanitizing semicolons. Since ; is the X-Stat field delimiter, any semicolon in a push option value breaks out of its designated field and creates new, attacker-controlled fields. They managed to literally do the simplest possible thing wrong. The fruit was hanging so low it might have been underground.
- irishcoffee 5mo agoOh Bobby Tables, your mom was quite clever.
- baccatore 5mo agoWhy do they need to stir up needless fear by using words like "BREAKING", "unauthorized access", or "millions of repositories" about the vulnerability that they caught before it was exploited in their X.com? https://x.com/wiz_io/status/2049153209982140718 https://x.com/wiz_io/status/2049153209982140718
- philipwhiuk 5mo agoNone of that is inaccurate? GitHub got lucky it was Wiz fuzzing them not state-sponsored agents?
- semiquaver 5mo agoBasically every single GitHub Enterprise Server deployment is still vulnerable to this bug. that is tens of thousands of appliances containing incredibly sensitive code. Also, this was about as bad as a vulnerability can get. It’s not exaggerating to say that all private code on GitHub should be considered compromised because of this issue. An anonymous user could have read every single private repo. To me, that warrants BREAKING.
- HenriTEL 5mo agoSo they had a security-critical header whose fields are set by their internal authentication service. And that same field can also contain arbitrary strings passed by the end user with git push -o I know it's easy to say after the fact but still, wtf
- melozo 5mo agoYeah I’m struggling to understand why the same header field would be used for git options in the first place. Why ever allow users to modify that specific header?
- fire2dev 5mo agoGraphite will soon be an alternative!