Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5005 articles · 188942 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-15996
GitHub · Enterprise Server

Denial of service vulnerability in GitHub Enterprise Server allowed unauthenticated service disruption via deeply nested request parameters

Description

A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause excessive CPU consumption and exhaust the pool of request-handling worker processes by sending a crafted form-encoded HTTP POST request containing deeply nested parameters. Because request parameters were parsed before routing and authentication, any POST endpoint could be used to trigger the condition, which could render the instance unresponsive. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.20.3, 3.19.7, 3.18.10, and 3.17.16.

Affected Products

VendorProductVersions
GitHubEnterprise Server3.17.0, 3.18.0, 3.19.0, 3.20.0

References

  • https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.16(release-notes)
  • https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.10(release-notes)
  • https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.7(release-notes)
  • https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.3(release-notes)

Related News (1 articles)

Tier C
VulDB6d ago
CVE-2026-15996 | GitHub Enterprise Server up to 3.17.15/3.18.9/3.19.6/3.20.2 resource consumption
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
CWECWE-674
PublishedAug 5, 2026
Last enriched6d ago
Trending Score13
Source articles1
Independent1
Info Completeness7/14
Missing: cvss, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-17556
Path traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance storage via the X-GitHub-Request-Id header
Trending: 20
CRITICALCVE-2026-15343
Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot dependency-file paths
Trending: 4
NONECVE-2026-15783
Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suites
Trending: 2
NONECVE-2026-15007
Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via deeply nested YAML in release notes configuration
Trending: 2
HIGHCVE-2026-50510EXP
GitHub Copilot Remote Code Execution Vulnerability
Trending: 1

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 5, 2026
Discovered by ZDM
Aug 5, 2026