CVE-2026-96890
- EPSS 0.41%
- Veröffentlicht 06.10.2026 19:18:17
- Zuletzt bearbeitet 07.10.2026 17:17:04
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed a repository contributor to cause the appliance to issue requests to attacker-controlled internal hosts, which could be chained to achieve remo...
- EPSS 0.45%
- Veröffentlicht 06.10.2026 19:17:39
- Zuletzt bearbeitet 07.10.2026 17:16:46
A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository collaborator with write access to delete the current default branch through the GraphQL API and cause an attacker-controlled branch to become t...
CVE-2026-75101
- EPSS 0.45%
- Veröffentlicht 22.09.2026 20:43:59
- Zuletzt bearbeitet 02.10.2026 18:46:47
An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch of pull requests in private repositories without authorization. Access tokens for raw p...
CVE-2026-77912
- EPSS 0.45%
- Veröffentlicht 22.09.2026 20:43:56
- Zuletzt bearbeitet 02.10.2026 18:38:48
A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because the Markdown rendering pipeline rewrote quote chara...
CVE-2026-77987
- EPSS 0.89%
- Veröffentlicht 22.09.2026 20:43:53
- Zuletzt bearbeitet 02.10.2026 18:37:45
A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the port, allowing requests to be dire...
CVE-2026-76851
- EPSS 0.44%
- Veröffentlicht 01.09.2026 21:55:10
- Zuletzt bearbeitet 08.09.2026 13:05:37
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance. Insufficient network isolation allowed malicious pre-receive hook code to impersonate an internal servic...
CVE-2026-19118
- EPSS 0.45%
- Veröffentlicht 01.09.2026 21:55:04
- Zuletzt bearbeitet 08.09.2026 13:08:54
A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution. Exploitation required an authenticated user with write access to a repository and precise timing of concurrent upl...
CVE-2026-18730
- EPSS 0.31%
- Veröffentlicht 01.09.2026 21:54:58
- Zuletzt bearbeitet 22.09.2026 21:17:30
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send crafted outbound requests to an attacker-controlled host. An unauthenticated endpoi...
CVE-2026-15996
- EPSS 0.44%
- Veröffentlicht 05.08.2026 20:12:57
- Zuletzt bearbeitet 18.08.2026 18:08:11
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause excessive CPU consumption and exhaust the pool of request-handling worker processes by sending a crafted form-encoded HTTP ...
CVE-2026-17556
- EPSS 0.5%
- Veröffentlicht 05.08.2026 20:05:53
- Zuletzt bearbeitet 18.08.2026 18:08:03
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including the entire user storage directory containing Git LFS objects, rele...