PT-2026-84531 · Github · Github Enterprise Server
CVSS v4.0
7.7
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
GitHub Enterprise Server versions prior to 3.22
Description
A time-of-check time-of-use (TOCTOU) race condition—a scenario where a system checks the state of a resource before using it, but the state changes between the check and the use—allows remote code execution. Exploitation requires an authenticated user with write access to a repository and precise timing of concurrent upload requests.
Recommendations
Update to version 3.17.20
Update to version 3.18.14
Update to version 3.19.11
Update to version 3.20.7
Update to version 3.21.5
Update to version 3.22.0
Fix
RCE
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Github Enterprise Server