« Back to list

Github

Github Enterprise Server: vulnerabilities and CVEs

Github Enterprise Server has 127 published vulnerabilities, 37 of them in the last 12 months. 15 are rated critical and 0 are listed by CISA as actively exploited.

CVEs127
Last 12 months37
Critical15
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-77987Critical (9.3)0.89%—Sep 22, 2026
A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the…
CVE-2026-77912High (7.4)0.45%—Sep 22, 2026
A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because the Markdown…
CVE-2026-75101Medium (6)0.45%—Sep 22, 2026
An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch of pull requests in private repositories without…
CVE-2026-76851High (7.7)0.83%—Sep 1, 2026
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance. Insufficient network isolation allowed malicious pre-receive hook code to…
CVE-2026-19118High (7.7)0.54%—Sep 1, 2026
A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution. Exploitation required an authenticated user with write access to a repository and…
CVE-2026-18730High (8.2)0.29%—Sep 1, 2026
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send crafted outbound requests to an attacker-controlled…
CVE-2026-15996Medium (6.6)0.77%—Aug 5, 2026
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause excessive CPU consumption and exhaust the pool of request-handling worker processes by…
CVE-2026-17556High (8.8)0.80%—Aug 5, 2026
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including the entire user storage directory…
CVE-2026-15783Medium (5.3)0.45%—Jul 17, 2026
A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata from private repositories they did not have access…
CVE-2026-15343High (8.6)0.75%—Jul 17, 2026
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to arbitrary repository paths, including…
CVE-2026-15007Medium (5.7)0.64%—Jul 17, 2026
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release notes configuration file containing deeply…
CVE-2026-14340Medium (5.3)0.43%—Jul 1, 2026
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App installation to perform certain write operations on public repositories…
CVE-2026-10585Medium (6.3)0.32%—Jun 30, 2026
A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to execute arbitrary JavaScript in another user's browser by injecting a crafted payload into…
CVE-2026-9132Medium (6)0.41%—Jun 30, 2026
—
CVE-2026-9106Medium (4.8)0.36%—Jun 30, 2026
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by…
CVE-2026-9312Critical (9.2)0.59%—May 27, 2026
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input…
CVE-2026-8606High (7)0.70%—May 27, 2026
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue HTTP requests to internal services via the security advisories package…
CVE-2026-8106Medium (5.9)0.26%—May 7, 2026
A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page that could allow credential theft. The redirect_to query parameter on the /setup/unlock endpoint was…
CVE-2026-8034High (7.9)0.86%—May 7, 2026
A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access internal services by exploiting URL parser confusion between the…
CVE-2026-7541Medium (6.3)0.66%—May 7, 2026
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause service disruption by sending crafted requests with deeply nested JSON payloads to an…
CVE-2026-6736Medium (6.3)0.41%—May 7, 2026
An authentication bypass vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to create a local user account, bypassing the configured external identity provider. When…
CVE-2026-5921High (8.9)0.65%—Apr 21, 2026
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to extract sensitive environment variables from the instance through a timing side-channel attack…
CVE-2026-5845High (7.2)0.48%—Apr 21, 2026
An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an authenticated attacker to access private repositories outside the intended installation…
CVE-2026-5512Medium (5.3)0.50%—Apr 21, 2026
An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to determine the names of private repositories by their numeric ID. The mobile upload policy API…
CVE-2026-4296High (7.5)0.74%—Apr 21, 2026
An incorrect regular expression vulnerability was identified in GitHub Enterprise Server that allowed an attacker to bypass OAuth redirect URI validation. An attacker with knowledge of a first-party OAuth application's…
CVE-2026-3307Medium (5.3)0.45%—Apr 21, 2026
An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an attacker with admin access on one repository to modify the secret scanning push protection delegated bypass reviewer list…
CVE-2026-3582Medium (5.3)0.40%—Mar 10, 2026
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with a classic personal access token (PAT) lacking the repo scope to retrieve issues and commits…
CVE-2026-2266High (7.4)0.18%—Mar 10, 2026
An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed DOM-based cross-site scripting via task list content. The task list content extraction logic did not properly…
CVE-2026-3854High (8.7)1.4%—Mar 10, 2026
An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to a repository to achieve remote code execution on the instance. During…
CVE-2026-3306Medium (5.3)0.43%—Mar 10, 2026
An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed a user with read access to a repository and write access to a project to modify issue and pull request metadata through the…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services3
  2. T1090 Proxy2
  3. T1190 Exploit Public-Facing Application2
  4. T1005 Data from Local System1
  5. T1059 Command and Scripting Interpreter1
  6. T1059.007 JavaScript1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Github