GitHub / Enterprise Server
124 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-77987 | GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgery | CRITICAL | 9.3 | Sep 22, 2026 |
| CVE-2026-77912 | Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed HTML attribute injection via the Markdown rendering pipeline | HIGH | 7.4 | Sep 22, 2026 |
| CVE-2026-75101 | Authorization bypass vulnerability in GitHub Enterprise Server allowed reading of private pull request diffs and patches via repository name collision | MEDIUM | 6.0 | Sep 22, 2026 |
| CVE-2026-76851 | Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed remote code execution via network access from pre-receive hooks to internal servi… | HIGH | 7.7 | Sep 1, 2026 |
| CVE-2026-19118 | Race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution | HIGH | 7.7 | Sep 1, 2026 |
| CVE-2026-18730 | Server-side request forgery vulnerability in GitHub Enterprise Server Manage API leaked a replayable gateway-agent bearer token | HIGH | 8.2 | Sep 1, 2026 |
| CVE-2026-15996 | Denial of service vulnerability in GitHub Enterprise Server allowed unauthenticated service disruption via deeply nested request parameters | MEDIUM | 6.6 | Aug 5, 2026 |
| CVE-2026-17556 | Path traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance storage via the X-GitHub-Request-Id header | HIGH | 8.8 | Aug 5, 2026 |
| CVE-2026-15783 | Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suites | MEDIUM | 5.3 | Jul 17, 2026 |
| CVE-2026-15343 | Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unch… | HIGH | 8.6 | Jul 17, 2026 |
| CVE-2026-15007 | Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via deeply nested YAML in release notes configuration | MEDIUM | 5.7 | Jul 17, 2026 |
| CVE-2026-14340 | An incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositories | MEDIUM | 5.3 | Jul 1, 2026 |
| CVE-2026-10585 | Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed arbitrary JavaScript execution via crafted Discussion titles in the Q&A category | MEDIUM | 6.3 | Jun 30, 2026 |
| CVE-2026-9132 | Missing authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository contents via the Copilot pull request diff summary end… | MEDIUM | 6.0 | Jun 30, 2026 |
| CVE-2026-9106 | UI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organization runner management via undisclosed OAuth scope on consent screen | MEDIUM | 4.8 | Jun 30, 2026 |
| CVE-2026-9312 | Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to internal services via path traversal in upload endpoint | CRITICAL | 9.2 | May 27, 2026 |
| CVE-2026-8606 | Server-Side Request Forgery in GitHub Enterprise Server via Advisory Package URL Endpoint | HIGH | 7.0 | May 26, 2026 |
| CVE-2026-8106 | Reflected HTML injection vulnerability in GitHub Enterprise Server Management Console login page allowed credential theft | MEDIUM | 5.9 | May 7, 2026 |
| CVE-2026-8034 | Server-side request forgery vulnerability in GitHub Enterprise Server notebook viewer via URL parser confusion | HIGH | 7.9 | May 7, 2026 |
| CVE-2026-7541 | Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via unauthenticated API endpoint | MEDIUM | 6.3 | May 7, 2026 |
| CVE-2026-6736 | Authentication bypass vulnerability in GitHub Enterprise Server allowed creation of local user accounts bypassing the configured external identity provider | MEDIUM | 6.3 | May 7, 2026 |
| CVE-2026-4821 | Proxy configuration command injection vulnerability found in GitHub Enterprise Server Management Console configuration API | n/a | Apr 21, 2026 | |
| CVE-2026-5845 | Improper authorization fallback allows scoped user-to-server token installation escape in GitHub Enterprise Server | HIGH | 7.2 | Apr 21, 2026 |
| CVE-2026-3307 | Authorization bypass in GitHub Enterprise Server secret scanning push protection allows cross-repository modification of delegated bypass reviewers | MEDIUM | 5.3 | Apr 21, 2026 |
| CVE-2026-5512 | Improper authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository names via mobile upload policy API | MEDIUM | 5.3 | Apr 21, 2026 |
Showing 1 to 25 of 124 CVEs