Github
Github Enterprise Server: vulnerabilidades y CVE
Github Enterprise Server tiene 127 vulnerabilidades publicadas, 37 de ellas en los últimos 12 meses. 15 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE127
Últimos 12 meses37
Críticas15
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-77987 | Crítica (9.3) | 0.89% | — | 22 sept 2026 | A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the… |
| CVE-2026-77912 | Alta (7.4) | 0.45% | — | 22 sept 2026 | A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because the Markdown… |
| CVE-2026-75101 | Media (6) | 0.45% | — | 22 sept 2026 | An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch of pull requests in private repositories without… |
| CVE-2026-76851 | Alta (7.7) | 0.83% | — | 1 sept 2026 | A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance. Insufficient network isolation allowed malicious pre-receive hook code to… |
| CVE-2026-19118 | Alta (7.7) | 0.54% | — | 1 sept 2026 | A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution. Exploitation required an authenticated user with write access to a repository and… |
| CVE-2026-18730 | Alta (8.2) | 0.29% | — | 1 sept 2026 | A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send crafted outbound requests to an attacker-controlled… |
| CVE-2026-15996 | Media (6.6) | 0.77% | — | 5 ago 2026 | A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause excessive CPU consumption and exhaust the pool of request-handling worker processes by… |
| CVE-2026-17556 | Alta (8.8) | 0.80% | — | 5 ago 2026 | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including the entire user storage directory… |
| CVE-2026-15783 | Media (5.3) | 0.45% | — | 17 jul 2026 | A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata from private repositories they did not have access… |
| CVE-2026-15343 | Alta (8.6) | 0.75% | — | 17 jul 2026 | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to arbitrary repository paths, including… |
| CVE-2026-15007 | Media (5.7) | 0.64% | — | 17 jul 2026 | A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release notes configuration file containing deeply… |
| CVE-2026-14340 | Media (5.3) | 0.43% | — | 1 jul 2026 | An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App installation to perform certain write operations on public repositories… |
| CVE-2026-10585 | Media (6.3) | 0.32% | — | 30 jun 2026 | A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to execute arbitrary JavaScript in another user's browser by injecting a crafted payload into… |
| CVE-2026-9132 | Media (6) | 0.41% | — | 30 jun 2026 | — |
| CVE-2026-9106 | Media (4.8) | 0.36% | — | 30 jun 2026 | A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by… |
| CVE-2026-9312 | Crítica (9.2) | 0.59% | — | 27 may 2026 | A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input… |
| CVE-2026-8606 | Alta (7) | 0.70% | — | 27 may 2026 | A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue HTTP requests to internal services via the security advisories package… |
| CVE-2026-8106 | Media (5.9) | 0.26% | — | 7 may 2026 | A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page that could allow credential theft. The redirect_to query parameter on the /setup/unlock endpoint was… |
| CVE-2026-8034 | Alta (7.9) | 0.86% | — | 7 may 2026 | A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access internal services by exploiting URL parser confusion between the… |
| CVE-2026-7541 | Media (6.3) | 0.66% | — | 7 may 2026 | A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause service disruption by sending crafted requests with deeply nested JSON payloads to an… |
| CVE-2026-6736 | Media (6.3) | 0.41% | — | 7 may 2026 | An authentication bypass vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to create a local user account, bypassing the configured external identity provider. When… |
| CVE-2026-5921 | Alta (8.9) | 0.65% | — | 21 abr 2026 | A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to extract sensitive environment variables from the instance through a timing side-channel attack… |
| CVE-2026-5845 | Alta (7.2) | 0.48% | — | 21 abr 2026 | An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an authenticated attacker to access private repositories outside the intended installation… |
| CVE-2026-5512 | Media (5.3) | 0.50% | — | 21 abr 2026 | An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to determine the names of private repositories by their numeric ID. The mobile upload policy API… |
| CVE-2026-4296 | Alta (7.5) | 0.74% | — | 21 abr 2026 | An incorrect regular expression vulnerability was identified in GitHub Enterprise Server that allowed an attacker to bypass OAuth redirect URI validation. An attacker with knowledge of a first-party OAuth application's… |
| CVE-2026-3307 | Media (5.3) | 0.45% | — | 21 abr 2026 | An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an attacker with admin access on one repository to modify the secret scanning push protection delegated bypass reviewer list… |
| CVE-2026-3582 | Media (5.3) | 0.40% | — | 10 mar 2026 | An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with a classic personal access token (PAT) lacking the repo scope to retrieve issues and commits… |
| CVE-2026-2266 | Alta (7.4) | 0.18% | — | 10 mar 2026 | An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed DOM-based cross-site scripting via task list content. The task list content extraction logic did not properly… |
| CVE-2026-3854 | Alta (8.7) | 1.4% | — | 10 mar 2026 | An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to a repository to achieve remote code execution on the instance. During… |
| CVE-2026-3306 | Media (5.3) | 0.43% | — | 10 mar 2026 | An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed a user with read access to a repository and write access to a project to modify issue and pull request metadata through the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.