GitHub Outage Map
The map below depicts the most recent cities worldwide where GitHub users have reported problems and outages. If you are having an issue with GitHub, make sure to submit a report below
The heatmap above shows where the most recent user-submitted and social media reports are geographically clustered. The density of these reports is depicted by the color scale as shown below.
GitHub users affected:
GitHub is a company that provides hosting for software development and version control using Git. It offers the distributed version control and source code management functionality of Git, plus its own features.
Most Affected Locations
Outage reports and issues in the past 15 days originated from:
| Location | Reports |
|---|---|
| Township of Evan, KS | 1 |
| Madrid, Madrid | 1 |
| Bogotá, Bogota D.C. | 1 |
| Paris, Île-de-France | 4 |
| Lyon, Auvergne-Rhône-Alpes | 2 |
| Lima, Lima | 1 |
| Aix-en-Provence, Provence-Alpes-Côte d'Azur | 1 |
| Trento, Trentino-Alto Adige | 1 |
| Le Chambon-Feugerolles, Auvergne-Rhône-Alpes | 1 |
| Antananarivo, Analamanga | 1 |
| Lure, Bourgogne-Franche-Comté | 1 |
| Ashkelon, Southern District | 1 |
| Veigné, Centre | 1 |
| Saint-Paul, Réunion | 2 |
| Mexico City, CDMX | 1 |
| León de los Aldama, GUA | 1 |
| Créteil, Île-de-France | 1 |
| Trichūr, KL | 1 |
| Brasília, DF | 1 |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
GitHub Issues Reports
Latest outage, problems and issue reports in social media:
-
Mukul Malik (@lazyynocturnal) reportedAnother use case. Ask fable first to identify top 20 bug/issue in front end or something that does not break and easy for agent to test e2e and logged them on github issue with all needed context. And then ask you chief of thread to split the work in few parallel threads so that they can work accordingly.
-
devvaibhav (@devvaibhav37) reportedThis is actually wild. Researchers found that malicious instructions hidden inside public GitHub issues could trick AI coding agents like Claude Code, Gemini CLI and Codex into doing things they shouldn't. In some cases, this could lead to credential theft, code execution and repository modification. The scary part? The attacker doesn't necessarily need to hack the AI itself. They just need to get the AI to read something malicious.
-
observer (@rznstn) reported@shettyprajwal_ @sidahuj @github You login into some indie app and they require too many permissions
-
PGHQ (@pghqdev) reported.@mattpocockuk Been living in your skills for a while now — love /research, use it constantly. But I've landed in a weird loop: /to-spec → /to-tickets cascades into tens or hundreds of GitHub issues, each spinning off ADRs and sub-tickets, half of them blocked and needing /wayfinder runs just to untangle. 24 hours later: 50% of my 200x Claude sub burned, 150 tickets churning (unblock → resolve → spawn more), and the codebase is maybe 30% further along, quality not up-to-the-par (worse than what I used to get with just rawdogging on top of a visual spec) Worst part: it's exhausting, not productive. Not complaining - genuinely curious. How should I actually be using this?
-
BE4TS (@Mr_ST4N) reportedGitHub suspended my account. No email, no clause cited — just "violation of ToS". I've appealed. OptiMax still works on your PC. Auto-updates and cloud sync are down. The old links are dead, so the name is now free. Any "OptiMax" download you see is NOT mine. Don't run it.
-
Sam A (@Kingjulian_i) reportedSome time ago, a dev mistakenly committed our stripe keys to GitHub ( we found out late ). Someone found It, used It to charge over 2k stolen cards $1 each. Stripe sent us an email hours later but It was already late. We lost over $3k from this issue alone . The same thing can be done with paystack
-
LetsGo (@askperp) reported@sidahuj @github Just talked me into locking all my accounts down
-
adriaan.com 📊 Simple Analytics (@adriaandotcom) reportedWant the same setup? Paste this into your LLM: Build a signed macOS broker app for a dedicated, least-privilege GitHub App. Install the signed app under the sandbox-protected `.agents` directory. Never whitelist a workspace-editable launcher. Store the GitHub App private key in a broker-only Data Protection Keychain access group. Add `***-stage`, `***-commit`, `***-push` and `gh` broker commands. Staging and committing must ignore host *** configuration, credentials, hooks and signing settings, and always use a fixed bot identity. Every push must: - Only allow `codex/*` branches. - Verify both author and committer. - Show the repository, branch and commit in a Touch ID prompt. - Require Touch ID every time. - Mint a short-lived, repository-scoped installation token. - Pass that token only to an isolated *** subprocess. - Cache it until expiry for approved `gh pr`, issue, workflow and other follow-up commands. Update `AGENTS.md` to forbid host `gh` credentials and direct `*** add`, `*** commit` or `*** push`. Add a Codex `PreToolUse` hook through `~/.codex/hooks.json` plus `.codex/rules` that deny direct *** mutations—including wrappers and help flags. Make the user run the installer, restart Codex and manually trust the hook. Test wrong-author pushes, hostile *** config and hooks, direct-push bypasses, token leakage and cached-token behavior.
-
Takopi🐙 (@OctopusTakopi) reportedgitHub is down again, looks like its time to selfhost
-
Roe Bit (@RoeBits) reported@MinModulation @Neo_Kaiser It's all going to be biased and what we dont know is how many modders are taken down without a fuss too Like All of these conflicts are hand picked, they're for points. Get a mega subscription or like a github or somethin. Decentralize. I hate this state of affairs regardless.
-
Mikchan (@m1kch4n) reported@Simeon_Cps My favorite part is when he does this, and he is completely ******* wrong. I then point out the obvious mistake, and he goes "Yes, you are right, this is on me" Like, for example, he once tried to pull a repo from my GitHub, it bugged out and only pulled half of the files. He immediately assumed that the repo was defective, tried to fix it, failed because I only added read permissions to the gh access token, still tried to fix it 15 times in different ways, and when he gave up, he started telling me the "bad news" that one of my public repos was totally ******, and started to give instructions and advices how to fix it. Dude, *** pull just bugged out for whatever reason. Simply run it again, ffs
-
Adel Bucetta (@adelbucetta) reported@sidahuj @github have you considered this might be an inside job? github's had issues before, it's not like they didn't see the signs coming
-
Slade 🛡️ LLM Hacker (@llm_redteam) reported@harleyfoote_ first read, no nudging needed. buried the instruction inside a github issue body and it fired the tool call right there.
-
Azzle (@AzzleAI) reported@GitHubCommunity, we’d really appreciate your help in raising awareness about this. Both our profile and repo are showing a 404, despite our work being merged into known projects’ skill libraries like @bankrbot. We also didn’t receive any email from GitHub about any issues with our account.
-
Critical Thinking - Bug Bounty Podcast (@ctbbpodcast) reportedCVE-2026-3854 was a GitHub RCE fired with `*** push -o`, the standard flag for passing arbitrary strings to the server, and those strings landed inside the internal header GitHub's own backend reads to decide what you are allowed to do, any authenticated user with push access to a repo could send it. The header is `X-Stat`, built by babeld out of the security policies gitauth hands back for your session, then parsed downstream by gitrpcd, which authenticates nothing itself and treats every field in it as authoritative. Fields are semicolon-delimited key=value pairs and duplicates resolve last-write-wins. babeld copied push option values in as `push_option_0` and friends without stripping semicolons, so a semicolon broke out of its field and everything behind it parsed as fresh fields, sitting later in the header than the legitimate ones. Three of those fields reach the pre-receive hook binary, `rails_env` picks between its two execution paths, sandboxed on production and running directly as the *** user on anything else, `custom_hooks_dir` sets the base directory for hook script lookup, `repo_pre_receive_hooks` carries JSON hook definitions, and a script field holding traversal resolves against that base directory to an arbitrary binary, which the unsandboxed path then executes. On GitHub the same chain went through as an ordinary push and nothing ran. Injecting `user_operator_mode=bool:true` for debug output showed the custom hooks step missing from the list, and the binary held a boolean marking enterprise mode, false there and injectable like everything else. Setting it landed execution as the *** user on a shared storage node holding other organisations' repositories.