Path Traversal Vulnerability in GitHub Enterprise Server
CVE-2026-17556
8.8HIGH
What is CVE-2026-17556?
A path traversal vulnerability in GitHub Enterprise Server allows unauthenticated attackers to delete any files and directories, including user storage containing Git Large File Storage objects, attachments, and avatars. The vulnerability arises from improper handling of the X-GitHub-Request-Id request header, which can lead to arbitrary file manipulation without requiring authentication. Attackers can exploit this flaw remotely, regardless of the instance's private mode setting. All versions prior to 3.22 are impacted, and users are urged to upgrade to the latest secure versions.
Affected Version(s)
Enterprise Server 3.17.0 <= 3.17.18
Enterprise Server 3.17.0 <= 3.17.18
Enterprise Server 3.18.0 <= 3.18.12