Server-Side Request Forgery Vulnerability in GitHub Enterprise Server
CVE-2026-18730
What is CVE-2026-18730?
A server-side request forgery (SSRF) vulnerability was found in GitHub Enterprise Server that enabled unauthenticated attackers to manipulate the Manage API. By sending specially crafted requests to an endpoint without proper path validation, attackers could direct the server to issue outbound calls to malicious hosts. This oversight allowed an adversary to intercept and replay authentication tokens against sensitive management agent endpoints. High-availability setups were immune due to topology restrictions. The issue was identified and reported through the GitHub Bug Bounty program and has since been resolved in the specified versions.
Affected Version(s)
Enterprise Server 3.17.0 <= 3.17.18
Enterprise Server 3.17.0 <= 3.17.18
Enterprise Server 3.18.0 <= 3.18.12