A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page that could allow credential theft. The redirect_to query parameter on the /setup/unlock endpoint was reflected into an HTML attribute without proper sanitization, enabling an attacker to inject a form element that could capture administrator credentials. Exploitation required an administrator to click a crafted link and enter their credentials. This vulnerability affected GitHub Enterprise Server versions 3.19.1 through 3.19.5 and 3.20.0 through 3.20.1, and was fixed in versions 3.19.6 and 3.20.2. This vulnerability was reported via the GitHub Bug Bounty program.
References
| Link | Resource |
|---|---|
| https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.6 | Release Notes Vendor Advisory |
| https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.2 | Release Notes Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
11 May 2026, 17:12
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
| First Time |
Github
Github enterprise Server |
|
| CPE | cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* | |
| References | () https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.6 - Release Notes, Vendor Advisory | |
| References | () https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.2 - Release Notes, Vendor Advisory |
07 May 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-07 22:16
Updated : 2026-05-11 17:12
NVD link : CVE-2026-8106
Mitre link : CVE-2026-8106
CVE.ORG link : CVE-2026-8106
JSON object : View
Products Affected
github
- enterprise_server
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
