Back

MEDIUM

Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via unauthenticated API endpoint

Published May 7, 2026

Description

A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause service disruption by sending crafted requests with deeply nested JSON payloads to an unauthenticated API endpoint. The endpoint parsed user-controlled JSON request bodies without size or depth limits, causing excessive CPU and memory consumption. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.20.2, 3.19.6, 3.18.9, 3.17.15, and 3.16.18. This vulnerability was reported via the GitHub Bug Bounty program.

Affected products

Remediation

No remediation recorded yet.

References (6)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_P
Published May 7, 2026
Updated May 8, 2026
Reserved Apr 30, 2026

CISA Vulnrichment

Updated May 8, 2026

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_P
Published May 7, 2026
Updated May 8, 2026

GitHub

No data