Race Condition Vulnerability in GitHub Enterprise Server
CVE-2026-19118

7.7HIGH

Key Information:

Vendor

Github

Vendor
CVE Published:
1 September 2026

What is CVE-2026-19118?

A race condition vulnerability was discovered in GitHub Enterprise Server that allows an authenticated user with write access to execute remote code via a precise timing of concurrent upload requests. All versions of GitHub Enterprise Server prior to 3.22 are vulnerable. The issue was reported through the GitHub Bug Bounty program and has been addressed in several subsequent releases.

Affected Version(s)

Enterprise Server 3.17.0 <= 3.17.19

Enterprise Server 3.17.0 <= 3.17.19

Enterprise Server 3.18.0 <= 3.18.13

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ahacker1
Harsh Jaiswal
.