PT-2026-68324 · Github · Enterprise Server
CVE-2026-15996
·
Published
2026-08-05
·
Updated
2026-08-18
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
GitHub Enterprise Server versions prior to 3.21
Description
An unauthenticated attacker can cause excessive CPU consumption and exhaust the pool of request-handling worker processes by sending a crafted form-encoded HTTP POST request containing deeply nested parameters. Since request parameters are parsed before routing and authentication, any POST endpoint can be used to trigger this condition, potentially rendering the instance unresponsive.
Recommendations
Update to version 3.20.3
Update to version 3.19.7
Update to version 3.18.10
Update to version 3.17.16
Fix
DoS
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Enterprise Server