Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4508 articles · 223849 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-77987PATCHED
GitHub · Enterprise Server

GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgery

Description

A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the port, allowing requests to be directed to internal services listening on other ports of the same appliance. Response bodies were not returned to the requester, but response timing acted as an oracle that allowed instance secrets to be extracted character by character. An extracted secret could then be used in a separate interaction with an internal service to obtain remote code execution on the appliance. Exploitation required network access to the instance and was unauthenticated when private mode was disabled, or required any authenticated user when private mode was enabled. This vulnerability affected GitHub Enterprise Server versions 3.17 through 3.22 and was fixed in versions 3.22.1, 3.21.6, 3.20.8, 3.19.12, 3.18.15, and 3.17.21. This vulnerability was reported through the GitHub Bug Bounty program.

Affected Products

VendorProductVersions
GitHubEnterprise Server3.17.0, 3.18.0, 3.19.0, 3.20.0, 3.21.0, 3.22.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftgithub enterprisecert_advisory90%

References

  • https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.21(release-notes)
  • https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.15(release-notes)
  • https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.12(release-notes)
  • https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.8(release-notes)
  • https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.6(release-notes)
  • https://docs.github.com/en/enterprise-server@3.22/admin/release-notes#3.22.1(release-notes)

Related News (2 articles)

Tier B
BSI Advisories4d ago
[NEU] [hoch] Microsoft GitHub Enterprise Server: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB5d ago
CVE-2026-77987 | GitHub Enterprise Server up to 3.22.0 Notebook Viewer server-side request forgery
→ No new info (linked only)

Discussion (0)

Loading…

CISA KEV❌ No
Actively exploited❌ No
Patch available
3.17.*3.18.*3.19.*3.20.*3.21.*3.22.*
CWECWE-918, CWE-208
PublishedSep 22, 2026
Last enriched5d ago
Trending Score27
Source articles2
Independent2
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-77912
Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed HTML attribute injection via the Markdown rendering pipeline
Trending: 20
NONECVE-2026-75101
Authorization bypass vulnerability in GitHub Enterprise Server allowed reading of private pull request diffs and patches via repository name collision
Trending: 17
NONECVE-2026-19118
Race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution
Trending: 15
NONECVE-2026-76851
Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed remote code execution via network access from pre-receive hooks to internal services
Trending: 2
NONECVE-2026-18730
Server-side request forgery vulnerability in GitHub Enterprise Server Manage API leaked a replayable gateway-agent bearer token
Trending: 2

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 22, 2026
Discovered by ZDM
Sep 22, 2026
Patch Available
Sep 23, 2026