skip to content
Back to
Home Bounties Research Advisories CodeQL Wall of Fame Get Involved Events
GitHub Security Lab

Securing the world's software, together

GitHub Security Lab

Securing the world's software, together

GitHub Security Lab’s mission is to inspire and enable the community to secure the open source software we all depend on.

Follow @GHSecurityLab

What we do

Find vulnerabilities
Find vulnerabilities

Our researchers find and report new vulnerabilities in the open source projects everyone relies on.

Educate the community
Educate the community

We share our research through proof-of-concepts, articles, tutorials, conferences and community events.

Amplify security research
Amplify security research

We scale the security research of our community by performing Variants Analysis for open source projects with CodeQL. Visit our CodeQL Wall of Fame.

Notify the ecosystem
Notify the ecosystem

We curate a database of CVEs and security advisories to notify open source developers and maintainers.

Our principles

Empower others
Empower others

Make securing open source easy for developers and maintainers.

Foster collaboration
Foster collaboration

Build a community of security researchers to serve the global open source community.

Vulnerabilities we've disclosed so far

  • GitHub Actions expression injection in BioDrop
    GHSL-2024-037 • published 2024/06/19 00:00:00 ago • discovered by Jorge Rosillo
  • Insufficient markdown sanitization in - CVE-2024-37304
    GHSL-2024-016CVE-2024-37304 • published 2024/06/19 00:00:00 ago • discovered by Jaroslav Lobacevski
  • Remote code execution (RCE) in UI for Apache Kafka - CVE-2023-52251, CVE-2024-32030
    GHSL-2023-229_GHSL-2023-230CVE-2023-52251CVE-2024-32030 • published 2024/06/19 00:00:00 ago • discovered by Michael Stepankin
  • Remote DoS and potential authentication bypasses in - CVE-2024-35221
    GHSL-2024-001_GHSL-2024-003CVE-2024-35221 • published 2024/06/14 00:00:00 ago • discovered by Peter Stöckli
  • Denial of Service (DoS) in Zammad - CVE-2024-33667
    GHSL-2024-029CVE-2024-33667 • published 2024/05/31 00:00:00 ago • discovered by Peter Stöckli
881 vulnerabilities found
by Security Lab researchers
635 CVEs credited

Meet the team

Alvaro Munoz

Hacking since 1970-01-01T00:00:00Z

GitHub icon @pwntester twitter icon @pwntester
Kevin Stubbings

Alright get out. From now on I'll do the memory managing around here.

GitHub icon @Kwstubbs
Jorge Rosillo

while true; do ./research; ./ctf; done

GitHub icon @jorgectf twitter icon @jorge_ctf
Jonathan Evans

Embracing the endless journey of cybersecurity discovery.

GitHub icon @jonathanlevans
Madison Oliver

Security transparency advocate

GitHub icon @taladrane twitter icon @taladrane
Nancy Gariché

Community Building as Secure Code

GitHub icon @nanzggits
Jonathan Moroney

Seeking safer software

GitHub icon @darakian twitter icon @Hooray_Darakian
Kevin Backhouse

Catching up on all the hacking that I should have done in the 1990s

GitHub icon @kevinbackhouse twitter icon @kevin_backhouse
Man Yue Mo

Security scavenger

GitHub icon @m-y-mo twitter icon @mmolgtm
Shelby Cunningham

Security person with a dash of data privacy

GitHub icon @shelbyc
Michael Stepankin

get shell or die trying.

GitHub icon @artsploit
Antonio Morales

EthicalHacker­BugHunter & C++; 3735928559

GitHub icon @antonio-morales twitter icon @nosoynadiemas
Joseph Katsioloudes

Making security easy for developers

GitHub icon @jkcso twitter icon @jkcso
Xavier René-Corail

3-legged race organizer: Building bridges between Dev and Sec

GitHub icon @xcorail twitter icon @xcorail
Peter Stöckli

Helping developers by breaking things.

GitHub icon @p- twitter icon @ulldma
Chamari Tucker

Hacker where? Hacker there.

GitHub icon @callmeMari
Sylwia Budzynska

*hacker voice* I’m in

GitHub icon @sylwia-budzynska twitter icon @BlazingWindSec
Jaroslav Lobacevski

Security panda

GitHub icon @jarlob twitter icon @yarlob
shape shape shape
mona puzzle

Join the effort

As a security researcher, your expertise is instrumental in securing the world’s software. Codify that knowledge as an expressive, executable, and repeatable CodeQL query that can be run on many codebases. Get rewarded for queries that have a positive impact on open source projects through our bounty program.

See our bounties

Our latest research

Coordinated vulnerability disclosure (CVD) for open source projects
A comprehensive guide for vulnerability reporters.
Nancy Gariché
February 9, 2022
Fuzzing sockets: Apache HTTP, Part 3: Results
In the finale of the Fuzzing sockets series, Antonio shares the results of his research on Apache HTTP server.
Antonio Morales
December 21, 2021
Getting root on Ubuntu through wishful thinking
How to exploit a double-free vulnerability in Ubuntu's accountsservice (CVE-2021-3939).
Kevin Backhouse
December 13, 2021