Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5049 articles · 189092 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-17556
github · enterprise server

Path traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance storage via the X-GitHub-Request-Id header

Description

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including the entire user storage directory containing Git LFS objects, release assets, attachments, and avatars. The X-GitHub-Request-Id request header was used without sanitization as a filesystem path segment for the upload buffer directory, so a traversal value pointed the buffer at an arbitrary path and the deferred cleanup routine recursively removed the traversed target. Exploitation required only network reachability to the instance and no authentication, and it worked even when private mode was enabled. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.4, 3.20.6, 3.19.10, 3.18.13 and 3.17.19. This vulnerability was reported via the GitHub Bug Bounty program.

Affected Products

VendorProductVersions
githubenterprise server3.17.0, 3.18.0, 3.19.0, 3.20.0, 3.21.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftgithub enterprisecert_advisory90%

References

  • https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.19(release-notes)
  • https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.13(release-notes)
  • https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.10(release-notes)
  • https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.6(release-notes)
  • https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.4(release-notes)

Related News (2 articles)

Tier B
BSI Advisories6d ago
[NEU] [hoch] Microsoft GitHub Enterprise: Schwachstelle ermöglicht Manipulation von Dateien
→ No new info (linked only)
Tier C
VulDB7d ago
CVE-2026-17556 | GitHub Enterprise Server up to 3.21.3 X-GitHub-Request-Id path traversal
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
CWECWE-22
PublishedAug 5, 2026
Trending Score20
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-15996
Denial of service vulnerability in GitHub Enterprise Server allowed unauthenticated service disruption via deeply nested request parameters
Trending: 13
CRITICALCVE-2026-15343
Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot dependency-file paths
Trending: 4
NONECVE-2026-15783
Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suites
Trending: 2
NONECVE-2026-15007
Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via deeply nested YAML in release notes configuration
Trending: 2
HIGHCVE-2026-50510EXP
GitHub Copilot Remote Code Execution Vulnerability
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 5, 2026
Discovered by ZDM
Aug 5, 2026