Github · Security Report CONFIDENTIAL
Scan Summary · 2026-05-01

Vulnerability findings for github.com

https://github.com/  ·  20.87.245.0

The latest scan identified 23 findings across the public-facing infrastructure. No critical or high-severity issues were observed in this run. 3 medium-severity item(s) should be scheduled for the next change window. Low: 9, Informational: 11.

Critical
0
High
0
Medium
3
Low
9
Info
11
REPORT  5c6aa6e9 SCAN  16:43 UTC TOOLS  httpx · nmap · zap
Medium severity 3 FINDINGS
M-01
CSP: style-src unsafe-inline
— · 5 instance(s)
Medium
M-02
Source Code Disclosure - SQL
— · 1 instance(s)
Medium
M-03
Sub Resource Integrity Attribute Missing
— · 5 instance(s)
Medium
Low severity 9 FINDINGS
L-01
Cookie No HttpOnly Flag
— · 3 instance(s)
Low
L-02
Cross-Domain JavaScript Source File Inclusion
— · 5 instance(s)
Low
L-03
Cross-Origin-Embedder-Policy Header Missing or Invalid
— · 3 instance(s)
Low
L-04
Cross-Origin-Opener-Policy Header Missing or Invalid
— · 3 instance(s)
Low
L-05
Cross-Origin-Resource-Policy Header Missing or Invalid
— · 4 instance(s)
Low
L-06
Information Disclosure - Debug Error Messages
— · 1 instance(s)
Low
L-07
Permissions Policy Header Not Set
— · 5 instance(s)
Low
L-08
Timestamp Disclosure - Unix
— · 5 instance(s)
Low
L-09
X-Content-Type-Options Header Missing
— · 3 instance(s)
Low
Informational 11 FINDINGS
3 network observation(s) on 20.87.245.0: ssh/22, http/80, https/443 plus httpx (1).

The detailed HTML report (full_vulnerable_reports) lists evidence, endpoints, and remediation text where the scanner provided it.

This message contains confidential security information.
Do not forward outside the intended recipient list.
REPORT 5c6aa6e9
2026-05-01

Github · Automated security scan summary