Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3485 articles · 157949 vulns · 36/41 feeds (7d)
← Back to list
—
CVE-2026-9312PATCHED
github · enterprise server

Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to internal services via path traversal in upload endpoint

Description

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload endpoint. By injecting path traversal content into request parameters, an attacker could bypass the intended request flow and redirect internal API calls, potentially accessing internal services and exposing sensitive credentials. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.16.20, 3.17.17, 3.18.11, 3.19.8, 3.20.4, and 3.21.1. This vulnerability was reported via the GitHub Bug Bounty program.

Affected Products

VendorProductVersions
githubenterprise server3.16.0, 3.17.0, 3.18.0, 3.19.0, 3.20.0, 3.21.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftgithub enterprisecert_advisory90%

References

  • https://docs.github.com/en/enterprise-server@3.16/admin/release-notes#3.16.20(release-notes)
  • https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.17(release-notes)
  • https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.11(release-notes)
  • https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.8(release-notes)
  • https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.4(release-notes)
  • https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.1(release-notes)

Related News (2 articles)

Tier B
BSI Advisories3d ago
[NEU] [hoch] Microsoft GitHub Enterprise: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen
→ No new info (linked only)
Tier C
VulDB3d ago
CVE-2026-9312 | GitHub Enterprise Server up to 3.21.0 Upload Endpoint server-side request forgery
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
3.21.1
CWECWE-918
PublishedMay 27, 2026
Last enriched3d agov2
Trending Score23
Source articles2
Independent2
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

PRE-CVEEXP
Supply Chain Compromise via Malicious Nx Console Visual Studio Code Extension v18.95.0
Trending: 34
CRITICALCVE-2026-8606
Server-Side Request Forgery in GitHub Enterprise Server via Advisory Package URL Endpoint
Trending: 27
MEDIUMCVE-2026-44837EXP
view_component: System Test Entry Point Path Check Allows Sibling Directory Escape
Trending: 27
MEDIUMCVE-2026-44836EXP
view_component: Preview Route Can Dispatch Inherited Helper Methods
Trending: 27
LOWCVE-2026-45803EXP
gh: GitHub Actions log output in `gh run view` allows terminal escape sequence injection
Trending: 14

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 27, 2026
Discovered by ZDM
May 27, 2026
Updated: severity, description
May 27, 2026
Patch Available
May 28, 2026

Version History

v2
Last enriched 3d ago
v2Tier C3d ago

Updated severity to CRITICAL, clarified exploit availability, and provided a more detailed description of the vulnerability.

severitydescription
via VulDB
v13d ago

Initial creation