Server-Side Request Forgery Vulnerability in GitHub Enterprise Server
CVE-2026-76851

7.7HIGH

Key Information:

Vendor

Github

Vendor
CVE Published:
1 September 2026

What is CVE-2026-76851?

A vulnerability in GitHub Enterprise Server enables Server-Side Request Forgery (SSRF), which could result in unauthorized remote code execution. The flaw stems from inadequate network isolation that permits malicious code within pre-receive hooks to impersonate internal services, potentially redirecting trusted internal requests to sensitive privileged services. To exploit this vulnerability, pre-receive hook networking must be activated, and the attacker must possess either site administrator privileges or write access to a repository configured with a pre-receive hook. This issue affects all versions of GitHub Enterprise Server prior to 3.22 and has been addressed in the releases of 3.17.20, 3.18.14, 3.19.11, 3.20.7, and 3.21.5 as part of routine security updates.

Affected Version(s)

Enterprise Server 3.17.0 <= 3.17.19

Enterprise Server 3.17.0 <= 3.17.19

Enterprise Server 3.18.0 <= 3.18.13

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

R31n
.