Path Traversal Vulnerability in GitHub Enterprise Server
CVE-2026-17556

8.8HIGH

Key Information:

Vendor

Github

Vendor
CVE Published:
5 August 2026

What is CVE-2026-17556?

A path traversal vulnerability in GitHub Enterprise Server allows unauthenticated attackers to delete any files and directories, including user storage containing Git Large File Storage objects, attachments, and avatars. The vulnerability arises from improper handling of the X-GitHub-Request-Id request header, which can lead to arbitrary file manipulation without requiring authentication. Attackers can exploit this flaw remotely, regardless of the instance's private mode setting. All versions prior to 3.22 are impacted, and users are urged to upgrade to the latest secure versions.

Affected Version(s)

Enterprise Server 3.17.0 <= 3.17.18

Enterprise Server 3.17.0 <= 3.17.18

Enterprise Server 3.18.0 <= 3.18.12

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

r31n
.