Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4508 articles · 223853 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-18730PATCHED
github · enterprise server

Server-side request forgery vulnerability in GitHub Enterprise Server Manage API leaked a replayable gateway-agent bearer token

Description

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send crafted outbound requests to an attacker-controlled host. An unauthenticated endpoint parsed an attacker-supplied cluster configuration and issued gateway-to-agent requests whose HMAC authenticated only a timestamp, not the request path or body. An attacker positioned to intercept the outbound request could capture this token and replay it against privileged management agent endpoints. High-availability deployments were not affected due to a topology restriction. This vulnerability affected GitHub Enterprise Server releases in the 3.17, 3.18, 3.19, 3.20, and 3.21 series and was fixed in versions 3.17.21, 3.18.15, 3.19.12, 3.20.8, and 3.21.6. This vulnerability was reported via the GitHub Bug Bounty program.

Affected Products

VendorProductVersions
githubenterprise server3.17.0, 3.18.0, 3.19.0, 3.20.0, 3.21.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftgithub enterprisecert_advisory90%

References

  • https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.21(release-notes)
  • https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.15(release-notes)
  • https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.12(release-notes)
  • https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.8(release-notes)
  • https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.6(release-notes)

Related News (2 articles)

Tier B
BSI Advisories25d ago
[NEU] [hoch] Microsoft GitHub Enterprise Server: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB26d ago
CVE-2026-18730 | GitHub Enterprise Server up to 3.21.3 Manage API server-side request forgery
→ No new info (linked only)

Discussion (0)

Loading…

CISA KEV❌ No
Actively exploited❌ No
Patch available
3.17.*3.18.*3.19.*3.20.*3.21.*
CWECWE-918
PublishedSep 1, 2026
Trending Score2
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-77987
GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgery
Trending: 27
NONECVE-2026-77912
Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed HTML attribute injection via the Markdown rendering pipeline
Trending: 20
NONECVE-2026-75101
Authorization bypass vulnerability in GitHub Enterprise Server allowed reading of private pull request diffs and patches via repository name collision
Trending: 17
NONECVE-2026-19118
Race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution
Trending: 15
NONECVE-2026-76851
Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed remote code execution via network access from pre-receive hooks to internal services
Trending: 2

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 1, 2026
Discovered by ZDM
Sep 1, 2026
Patch Available
Sep 22, 2026