Skip to content
githubCVE-2026-77987

A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server.

Critical9.3CVE-2026-77987 · Published Sep 22, 2026 · updated Sep 24, 2026

Source advisory

Affected versions

PackageAffectedFixed in
Enterprise Server
Vendor
>= 3.17.0, < 3.17.*3.17.*
>= 3.18.0, < 3.18.*3.18.*
>= 3.19.0, < 3.19.*3.19.*
>= 3.20.0, < 3.20.*3.20.*
Details and references

A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the port, allowing requests to be directed to internal services listening on other ports of the same appliance. Response bodies were not returned to the requester, but response timing acted as an oracle that allowed instance secrets to be extracted character by character. An extracted secret could then be used in a separate interaction with an internal service to obtain remote code execution on the appliance. Exploitation required network access to the instance and was unauthenticated when private mode was disabled, or required any authenticated user when private mode was enabled. This vulnerability affected GitHub Enterprise Server versions 3.17 through 3.22 and was fixed in versions 3.22.1, 3.21.6, 3.20.8, 3.19.12, 3.18.15, and 3.17.21. This vulnerability was reported through the GitHub Bug Bounty program.

CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
no source yet
Weakness
CWE-208, CWE-918

More github advisories

All
DateAdvisory
Sep 22An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch of pull requests in private...
CVE-2026-75101Medium6.0fixed in Enterprise Server 3.17.*, Enterprise Server 3.18.*, Enterprise Server 3.19.*
Sep 22A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because...
CVE-2026-77912High7.4fixed in Enterprise Server 3.17.*, Enterprise Server 3.18.*, Enterprise Server 3.19.*
Sep 23gh-aw: HTTPS egress allowlist bypass via TLS SNI domain fronting
GHSA-x78f-wrrj-4h24High8.3fixed in 0.89.17
Sep 1A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance.
CVE-2026-76851High7.7no fix yet
Sep 1A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution.
CVE-2026-19118High7.7no fix yet
Sep 1A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send crafted outbound requests to an...
CVE-2026-18730High8.2fixed in Enterprise Server 3.17.*, Enterprise Server 3.18.*, Enterprise Server 3.19.*

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.