A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause service disruption by sending crafted requests with deeply nested JSON payloads to an unauthenticated API endpoint. The endpoint parsed user-controlled JSON request bodies without size or depth limits, causing excessive CPU and memory consumption. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.20.2, 3.19.6, 3.18.9, 3.17.15, and 3.16.18. This vulnerability was reported via the GitHub Bug Bounty program.
References
| Link | Resource |
|---|---|
| https://docs.github.com/en/enterprise-server@3.16/admin/release-notes#3.16.18 | Release Notes Vendor Advisory |
| https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.15 | Release Notes Vendor Advisory |
| https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.9 | Release Notes Vendor Advisory |
| https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.6 | Release Notes Vendor Advisory |
| https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.2 | Release Notes Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
11 May 2026, 17:19
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| First Time |
Github
Github enterprise Server |
|
| CPE | cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* | |
| References | () https://docs.github.com/en/enterprise-server@3.16/admin/release-notes#3.16.18 - Release Notes, Vendor Advisory | |
| References | () https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.15 - Release Notes, Vendor Advisory | |
| References | () https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.9 - Release Notes, Vendor Advisory | |
| References | () https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.6 - Release Notes, Vendor Advisory | |
| References | () https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.2 - Release Notes, Vendor Advisory |
07 May 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-07 22:16
Updated : 2026-05-11 17:19
NVD link : CVE-2026-7541
Mitre link : CVE-2026-7541
CVE.ORG link : CVE-2026-7541
JSON object : View
Products Affected
github
- enterprise_server
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
