Server-Side Request Forgery Vulnerability in GitHub Enterprise Server
CVE-2026-9312
9.2CRITICAL
What is CVE-2026-9312?
A server-side request forgery (SSRF) vulnerability was detected in GitHub Enterprise Server, allowing unauthenticated attackers to exploit insufficient input validation in an upload endpoint. By using crafted requests with path traversal content, attackers could manipulate the intended request flow and redirect internal API calls, leading to unauthorized access to internal services and potential exposure of sensitive information. This issue impacted all versions prior to 3.22 and has been addressed in later versions.
Affected Version(s)
Enterprise Server 3.16.0 <= 3.16.19
Enterprise Server 3.16.0 <= 3.16.19
Enterprise Server 3.17.0 <= 3.17.16