Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Griffinf

#33130of 56,327
8.2Total CVSS
Vulnerabilities · 1
PT-2026-84530
8.2
2026-09-01
Github · Github Enterprise Server · CVE-2026-18730
**Name of the Vulnerable Software and Affected Versions** GitHub Enterprise Server versions prior to 3.22 **Description** A server-side request forgery (SSRF) issue exists in the Manage API, allowing an unauthenticated attacker to force the server to send crafted outbound requests to a host under their control. This occurs because an unauthenticated endpoint parses a cluster configuration provided by the attacker and issues gateway-to-agent requests where the HMAC (Hash-based Message Authentication Code, a mechanism for verifying data integrity and authenticity) only authenticates a timestamp rather than the request path or body. An attacker capable of intercepting these outbound requests can capture the token and replay it against privileged management agent endpoints. High-availability deployments are not affected. **Recommendations** Update to version 3.17.19 Update to version 3.18.13 Update to version 3.19.10 Update to version 3.20.6 Update to version 3.21.4