Skip to content
githubCVE-2026-19118

A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution.

High7.7CVE-2026-19118 · Published Sep 1, 2026 · updated Sep 8, 2026

Source advisory

Affected versions

PackageAffectedFixed in
Enterprise Server
Vendor
>= 3.17.0, <= 3.17.19No fix yet
>= 3.18.0, <= 3.18.13No fix yet
>= 3.19.0, <= 3.19.10No fix yet
>= 3.20.0, <= 3.20.6No fix yet
Details and references

A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution. Exploitation required an authenticated user with write access to a repository and precise timing of concurrent upload requests. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.17.20, 3.18.14, 3.19.11, 3.20.7, and 3.21.5. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
no source yet
Weakness
CWE-367

More github advisories

All
DateAdvisory
Sep 1A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send crafted outbound requests to an...
CVE-2026-18730High8.2fixed in Enterprise Server 3.17.*, Enterprise Server 3.18.*, Enterprise Server 3.19.*
Sep 1A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance.
CVE-2026-76851High7.7no fix yet
Aug 29Arbitrary host filesystem & Docker-socket mounts via MCP server `mounts`
GHSA-846c-fpfg-rj9mCritical9.6no fix yet
Aug 27Safe-output artifacts may expose CI trigger tokens
GHSA-8h78-hpm7-29ggCritical9.1fixed in 0.85.4
Aug 25gh-aw: github.event.* command injection via heredoc-blind template guardrails (MCP config, all engines)
GHSA-796c-cr8h-rr49High8.5no fix yet
Aug 16gh-aw: cache-memory restores an attacker-controlled .git/config and executes a git filter driver on the runner host
GHSA-gh77-fhfh-2mc5High8.5fixed in v0.87.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.