Server-Side Request Forgery Vulnerability in GitHub Enterprise Server
CVE-2026-18730

8.2HIGH

Key Information:

Vendor

Github

Vendor
CVE Published:
1 September 2026

What is CVE-2026-18730?

A server-side request forgery (SSRF) vulnerability was found in GitHub Enterprise Server that enabled unauthenticated attackers to manipulate the Manage API. By sending specially crafted requests to an endpoint without proper path validation, attackers could direct the server to issue outbound calls to malicious hosts. This oversight allowed an adversary to intercept and replay authentication tokens against sensitive management agent endpoints. High-availability setups were immune due to topology restrictions. The issue was identified and reported through the GitHub Bug Bounty program and has since been resolved in the specified versions.

Affected Version(s)

Enterprise Server 3.17.0 <= 3.17.18

Enterprise Server 3.17.0 <= 3.17.18

Enterprise Server 3.18.0 <= 3.18.12

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

griffinf
.