Denial of Service Vulnerability in GitHub Enterprise Server
CVE-2026-7541
6.3MEDIUM
What is CVE-2026-7541?
A vulnerability in GitHub Enterprise Server was discovered that allows unauthenticated attackers to disrupt service by sending specially crafted requests containing deeply nested JSON payloads to an unsecured API endpoint. This vulnerability results in excessive CPU and memory consumption as the endpoint processes user-controlled JSON request bodies without any size or depth restrictions. All versions prior to 3.21 of GitHub Enterprise Server are impacted. The issue was addressed in subsequent releases which resolved the underlying problems.
Affected Version(s)
Enterprise Server 3.16.0 <= 3.16.17
Enterprise Server 3.16.0 <= 3.16.17
Enterprise Server 3.17.0 <= 3.17.14