A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload endpoint. By injecting path traversal content into request parameters, an attacker could bypass the intended request flow and redirect internal API calls, potentially accessing internal services and exposing sensitive credentials. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.16.20, 3.17.17, 3.18.11, 3.19.8, 3.20.4, and 3.21.1. This vulnerability was reported via the GitHub Bug Bounty program.
References
| Link | Resource |
|---|---|
| https://docs.github.com/en/enterprise-server@3.16/admin/release-notes#3.16.20 | Product Release Notes |
| https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.17 | Product Release Notes |
| https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.11 | Product Release Notes |
| https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.8 | Product Release Notes |
| https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.4 | Product Release Notes |
| https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.1 | Product Release Notes |
Configurations
Configuration 1 (hide)
|
History
02 Jun 2026, 18:31
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://docs.github.com/en/enterprise-server@3.16/admin/release-notes#3.16.20 - Product, Release Notes | |
| References | () https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.17 - Product, Release Notes | |
| References | () https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.11 - Product, Release Notes | |
| References | () https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.8 - Product, Release Notes | |
| References | () https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.4 - Product, Release Notes | |
| References | () https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.1 - Product, Release Notes | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.2 |
| CPE | cpe:2.3:a:github:enterprise_server:3.21.1:rc1:*:*:*:*:*:* cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* |
|
| First Time |
Github enterprise Server
Github |
27 May 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-27 00:16
Updated : 2026-06-02 18:31
NVD link : CVE-2026-9312
Mitre link : CVE-2026-9312
CVE.ORG link : CVE-2026-9312
JSON object : View
Products Affected
github
- enterprise_server
CWE
CWE-918
Server-Side Request Forgery (SSRF)
