GitHub Security Lab

Securing the world's software, together

GitHub Security Lab

Securing the world's software, together

GitHub Security Lab’s mission is to inspire and enable the community to secure the open source software we all depend on.

Follow @GHSecurityLab

What we do

Find vulnerabilities
Find vulnerabilities

Our researchers find and report new vulnerabilities in the open source projects everyone relies on.

Empower others
Empower others

We build tools like CodeQL to make security easy for anyone working to secure open source.

Foster collaboration
Foster collaboration

We're building a community of security researchers and an open coalition of the world's security teams.

Vulnerabilities we've disclosed

  • XSS vulnerability in hotspot link
    CVE-2019-16763 • Pannellum • published 15 days ago • discovered by Max Schaefer
  • Integer overflow in amqp_handle_input
    CVE-2019-18609 • rabbitmq-c • published a month ago • discovered by Agustin Gianni
  • Remote denial of service or possible information disclosure when connecting to a malicious SSH server
    CVE-2019-17498 • libssh2 • published 2 months ago • discovered by Kevin Backhouse
  • Heap-based overflow in contrib/pmaixforwardedfrom/pmaixforwardedfrom.c
    CVE-2019-17041 • rsyslog • published 2 months ago • discovered by Agustin Gianni
  • Out-of-bounds read in contrib/pmdb2diag/pmdb2diag.c
    CVE-2019-17040 • rsyslog • published 2 months ago • discovered by Agustin Gianni
114 CVEs found
by Security Lab researchers

Meet the team

Nico Waisman

Open Source Entomologist

Kevin Backhouse

Compilers, program analysis, security research

Man Yue Mo

Security scavenger

Agustin Gianni

Avoiding grep since 1999 AD

Antonio Morales

EthicalHacker'­BugHunter & C++; 3735928559

Xavier René-Corail

3-legged race organizer: Building bridges between Dev and Sec

Sam Lanning

Making security easier than gpg



We’re building a coalition of companies who share our belief that the security of open source is important for everyone. Our initial partners have all committed to contribute in different forms to achieving this goal. We invite others to join the effort.

Microsoft logo

Our tools

Our industry-leading code analysis engine, CodeQL, is now free for use on open source. CodeQL lets you query code as though it were data. Write a query to find all variants of a vulnerability, eradicating it forever. Then share your query to help others do the same.

Download CodeQL

Join the effort

As a security researcher, your expertise is instrumental in securing the world’s software. Codify that knowledge as an expressive, executable, and repeatable CodeQL query that can be run on many codebases. Get rewarded for queries that have a positive impact on open source projects through our bounty program.

See our bounties