Github · Github Enterprise Server · CVE-2026-18730
**Name of the Vulnerable Software and Affected Versions**
GitHub Enterprise Server versions prior to 3.22
**Description**
A server-side request forgery (SSRF) issue exists in the Manage API, allowing an unauthenticated attacker to force the server to send crafted outbound requests to a host under their control. This occurs because an unauthenticated endpoint parses a cluster configuration provided by the attacker and issues gateway-to-agent requests where the HMAC (Hash-based Message Authentication Code, a mechanism for verifying data integrity and authenticity) only authenticates a timestamp rather than the request path or body. An attacker capable of intercepting these outbound requests can capture the token and replay it against privileged management agent endpoints. High-availability deployments are not affected.
**Recommendations**
Update to version 3.17.19
Update to version 3.18.13
Update to version 3.19.10
Update to version 3.20.6
Update to version 3.21.4