Server-Side Request Forgery in GitHub Enterprise Server
CVE-2026-96890

8.7HIGH

Key Information:

Vendor

Github

Vendor
CVE Published:
6 October 2026

What is CVE-2026-96890?

A Server-Side Request Forgery (SSRF) vulnerability in GitHub Enterprise Server allows authenticated contributors to exploit the system, potentially issuing requests to malicious internal hosts. This could lead to remote code execution when combined with other exploits. The vulnerability arises from improper trust in GCP service account credentials, enabling requests to unauthorized token endpoints. Affected users must be authenticated with repository push permissions, particularly on configurations utilizing GitHub Advanced Security. The issue has been resolved in the latest releases.

Affected Version(s)

Enterprise Server 3.20.0 < 3.20.*

Enterprise Server 3.21.0 < 3.21.*

Enterprise Server 3.22.0 < 3.22.*

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

R31n
.