Server-Side Request Forgery Vulnerability in GitHub Enterprise Server
CVE-2026-76851
What is CVE-2026-76851?
A vulnerability in GitHub Enterprise Server enables Server-Side Request Forgery (SSRF), which could result in unauthorized remote code execution. The flaw stems from inadequate network isolation that permits malicious code within pre-receive hooks to impersonate internal services, potentially redirecting trusted internal requests to sensitive privileged services. To exploit this vulnerability, pre-receive hook networking must be activated, and the attacker must possess either site administrator privileges or write access to a repository configured with a pre-receive hook. This issue affects all versions of GitHub Enterprise Server prior to 3.22 and has been addressed in the releases of 3.17.20, 3.18.14, 3.19.11, 3.20.7, and 3.21.5 as part of routine security updates.
Affected Version(s)
Enterprise Server 3.17.0 <= 3.17.19
Enterprise Server 3.17.0 <= 3.17.19
Enterprise Server 3.18.0 <= 3.18.13