PT-2026-84530 · Github · Github Enterprise Server

·

CVE-2026-18730

·

Published

2026-09-01

·

Updated

2026-09-03

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions GitHub Enterprise Server versions prior to 3.22
Description A server-side request forgery (SSRF) issue exists in the Manage API, allowing an unauthenticated attacker to force the server to send crafted outbound requests to a host under their control. This occurs because an unauthenticated endpoint parses a cluster configuration provided by the attacker and issues gateway-to-agent requests where the HMAC (Hash-based Message Authentication Code, a mechanism for verifying data integrity and authenticity) only authenticates a timestamp rather than the request path or body. An attacker capable of intercepting these outbound requests can capture the token and replay it against privileged management agent endpoints. High-availability deployments are not affected.
Recommendations Update to version 3.17.19 Update to version 3.18.13 Update to version 3.19.10 Update to version 3.20.6 Update to version 3.21.4

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18730

Affected Products

Github Enterprise Server