CVE-2026-8606

A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue HTTP requests to internal services via the security advisories package lookup feature. By directing requests to an internal management service and measuring response timing, an attacker could infer the values of sensitive environment variables, including signing secrets and private keys. Exploitation required GitHub Packages to be enabled; on instances not running in private mode the vulnerability was exploitable without authentication, otherwise any authenticated user could exploit it. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21.1 and was fixed in versions 3.20.3, 3.19.7, 3.18.10, 3.17.16, and 3.16.19. This vulnerability was reported via the GitHub Bug Bounty program.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*
cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*
cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*
cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*
cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*
cpe:2.3:a:github:enterprise_server:3.21.0:*:*:*:*:*:*:*

History

23 Jul 2026, 11:10

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de falsificación de petición del lado del servidor (SSRF) fue identificada en GitHub Enterprise Server que permitía a un atacante hacer que el servidor emitiera peticiones HTTP a servicios internos a través de la función de búsqueda de paquetes de avisos de seguridad. Al dirigir peticiones a un servicio de gestión interno y medir el tiempo de respuesta, un atacante podría inferir los valores de variables de entorno sensibles, incluyendo secretos de firma y claves privadas. La explotación requería que GitHub Packages estuviera habilitado; en instancias que no se ejecutaban en modo privado, la vulnerabilidad era explotable sin autenticación, de lo contrario, cualquier usuario autenticado podría explotarla. Esta vulnerabilidad afectaba a todas las versiones de GitHub Enterprise Server anteriores a la 3.21.1 y fue corregida en las versiones 3.20.3, 3.19.7, 3.18.10, 3.17.16 y 3.16.19. Esta vulnerabilidad fue reportada a través del programa GitHub Bug Bounty.

01 Jun 2026, 18:33

Type Values Removed Values Added
References () https://docs.github.com/en/enterprise-server@3.16/admin/release-notes#3.16.19 - () https://docs.github.com/en/enterprise-server@3.16/admin/release-notes#3.16.19 - Product, Release Notes
References () https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.16 - () https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.16 - Product, Release Notes
References () https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.10 - () https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.10 - Product, Release Notes
References () https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.7 - () https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.7 - Product, Release Notes
References () https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.3 - () https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.3 - Product, Release Notes
References () https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.1 - () https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.1 - Product, Release Notes
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9
First Time Github enterprise Server
Github
CPE cpe:2.3:a:github:enterprise_server:3.21.0:*:*:*:*:*:*:*
cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*

27 May 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-27 00:16

Updated : 2026-07-23 11:10


NVD link : CVE-2026-8606

Mitre link : CVE-2026-8606

CVE.ORG link : CVE-2026-8606


JSON object : View

Products Affected

github

  • enterprise_server
CWE
CWE-918

Server-Side Request Forgery (SSRF)