GitHub Pays $100,000 Bounty for Critical RCE Flaw in Git Push Pipeline

GitHub has awarded security researcher Saif Ghani a $100,000 bug bounty after the disclosure of CVE-2026-3854, a critical remote code execution vulnerability affecting GitHub’s Git push processing pipeline. The reward is reportedly the largest publicly disclosed payment made through GitHub’s Vulnerability Reward Program. Ghani, known on X as @sagitz_, announced the bounty on July 22, […]

This article has been indexed from Cyber Security News

Read the original article: