PT-2026-97052 · Github · Github Enterprise Server

·

CVE-2026-77987

·

Published

2026-09-22

·

Updated

2026-09-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GitHub Enterprise Server versions 3.17 through 3.22
Description A server-side request forgery (SSRF) issue exists in the notebook viewer. While the system validates the scheme and host of a user-supplied URL, it fails to validate the port. This allows requests to be directed to internal services listening on different ports of the same appliance. Although response bodies are not returned, response timing serves as an oracle, enabling the character-by-character extraction of instance secrets. These secrets can subsequently be used in interactions with internal services to achieve remote code execution (RCE) on the appliance. Exploitation requires network access and is unauthenticated if private mode is disabled, or requires any authenticated user if private mode is enabled.
Recommendations Update version 3.17 to 3.17.21 Update version 3.18 to 3.18.15 Update version 3.19 to 3.19.12 Update version 3.20 to 3.20.8 Update version 3.21 to 3.21.6 Update version 3.22 to 3.22.1

Fix

RCE

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77987

Affected Products

Github Enterprise Server