Denial of Service Vulnerability in GitHub Enterprise Server
CVE-2026-15996

6.6MEDIUM

Key Information:

Vendor

Github

Vendor
CVE Published:
5 August 2026

What is CVE-2026-15996?

A denial of service vulnerability has been identified in GitHub Enterprise Server, allowing unauthenticated attackers to trigger excessive CPU usage. By exploiting a crafted form-encoded HTTP POST request with deeply nested parameters, attackers can exhaust the pool of request-handling worker processes. This vulnerability affects all versions of GitHub Enterprise Server prior to 3.21 and can render the instance unresponsive due to improper request parameter parsing prior to routing and authentication. The flaw was addressed in versions 3.20.3, 3.19.7, 3.18.10, and 3.17.16.

Affected Version(s)

Enterprise Server 3.17.0 <= 3.17.15

Enterprise Server 3.17.0 <= 3.17.15

Enterprise Server 3.18.0 <= 3.18.9

References

CVSS V4

Score:
6.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.