Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3486 articles · 157946 vulns · 36/41 feeds (7d)
← Back to list
—
CVE-2026-8606PATCHED
github · enterprise server

Server-Side Request Forgery in GitHub Enterprise Server via Advisory Package URL Endpoint

Description

A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue HTTP requests to internal services via the security advisories package lookup feature. By directing requests to an internal management service and measuring response timing, an attacker could infer the values of sensitive environment variables, including signing secrets and private keys. Exploitation required GitHub Packages to be enabled; on instances not running in private mode the vulnerability was exploitable without authentication, otherwise any authenticated user could exploit it. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21.1 and was fixed in versions 3.20.3, 3.19.7, 3.18.10, 3.17.16, and 3.16.19. This vulnerability was reported via the GitHub Bug Bounty program.

Affected Products

VendorProductVersions
githubenterprise server3.21.0, 3.20.0, 3.19.0, 3.18.0, 3.17.0, 3.16.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftgithub enterprisecert_advisory90%

References

  • https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.1(release-notes)
  • https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.3(release-notes)
  • https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.7(release-notes)
  • https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.10(release-notes)
  • https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.16(release-notes)
  • https://docs.github.com/en/enterprise-server@3.16/admin/release-notes#3.16.19(release-notes)

Related News (2 articles)

Tier B
BSI Advisories3d ago
[NEU] [hoch] Microsoft GitHub Enterprise: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen
→ No new info (linked only)
Tier C
VulDB3d ago
CVE-2026-8606 | GitHub Enterprise Server up to 3.21.0 server-side request forgery
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
3.21.1
CWECWE-918
PublishedMay 26, 2026
Last enriched3d agov2
Trending Score27
Source articles2
Independent2
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

PRE-CVEEXP
Supply Chain Compromise via Malicious Nx Console Visual Studio Code Extension v18.95.0
Trending: 34
MEDIUMCVE-2026-44837EXP
view_component: System Test Entry Point Path Check Allows Sibling Directory Escape
Trending: 27
MEDIUMCVE-2026-44836EXP
view_component: Preview Route Can Dispatch Inherited Helper Methods
Trending: 27
NONECVE-2026-9312
Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to internal services via path traversal in upload endpoint
Trending: 23
LOWCVE-2026-45803EXP
gh: GitHub Actions log output in `gh run view` allows terminal escape sequence injection
Trending: 14

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 26, 2026
Discovered by ZDM
May 27, 2026
Patch Available
May 27, 2026
Updated: severity
May 27, 2026

Version History

v2
Last enriched 3d ago
v2Tier C3d ago

Updated severity to CRITICAL and noted that no exploit is available.

severity
via VulDB
v13d ago

Initial creation