Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223839 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-75101PATCHED
GitHub · Enterprise Server

Authorization bypass vulnerability in GitHub Enterprise Server allowed reading of private pull request diffs and patches via repository name collision

Description

An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch of pull requests in private repositories without authorization. Access tokens for raw pull request diffs and patches were scoped to the repository name and pull request number rather than to a globally unique repository identifier, so an attacker who created a repository and pull request matching a target's repository name and pull request number could use a token for their own repository to retrieve the private pull request's contents. Exploitation required the attacker to know the target repository's name and a valid pull request number. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.17.21, 3.18.15, 3.19.12, 3.20.8, and 3.21.6. This vulnerability was reported via the GitHub Bug Bounty program.

Affected Products

VendorProductVersions
GitHubEnterprise Server3.17.0, 3.18.0, 3.19.0, 3.20.0, 3.21.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftgithub enterprisecert_advisory90%

References

  • https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.21(release-notes)
  • https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.15(release-notes)
  • https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.12(release-notes)
  • https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.8(release-notes)
  • https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.6(release-notes)

Related News (2 articles)

Tier B
BSI Advisories4d ago
[NEU] [hoch] Microsoft GitHub Enterprise Server: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB5d ago
CVE-2026-75101 | GitHub Enterprise Server up to 3.21.x authorization
→ No new info (linked only)

Discussion (0)

Loading…

CISA KEV❌ No
Actively exploited❌ No
Patch available
3.17.*3.18.*3.19.*3.20.*3.21.*
CWECWE-639
PublishedSep 22, 2026
Last enriched5d ago
Trending Score17
Source articles2
Independent2
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-77987
GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgery
Trending: 27
NONECVE-2026-77912
Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed HTML attribute injection via the Markdown rendering pipeline
Trending: 21
NONECVE-2026-19118
Race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution
Trending: 15
NONECVE-2026-76851
Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed remote code execution via network access from pre-receive hooks to internal services
Trending: 2
NONECVE-2026-18730
Server-side request forgery vulnerability in GitHub Enterprise Server Manage API leaked a replayable gateway-agent bearer token
Trending: 2

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 22, 2026
Discovered by ZDM
Sep 22, 2026
Patch Available
Sep 23, 2026