
GitHub Pays $100,000 Bounty for Critical RCE Flaw in Git Push Pipeline
GitHub has awarded security researcher Saif Ghani a $100,000 bug bounty after the disclosure of CVE-2026-3854, a critical remote code execution vulnerability affecting GitHub’s Git push processing pipeline. The reward is reportedly the largest publicly disclosed payment made through GitHub’s Vulnerability Reward Program. Ghani, known on X as @sagitz_, announced the bounty on July 22, […]
The post GitHub Pays $100,000 Bounty for Critical RCE Flaw in Git Push Pipeline appeared first on Cyber Security News.