Server-Side Request Forgery in GitHub Enterprise Server
CVE-2026-96890
8.7HIGH
What is CVE-2026-96890?
A Server-Side Request Forgery (SSRF) vulnerability in GitHub Enterprise Server allows authenticated contributors to exploit the system, potentially issuing requests to malicious internal hosts. This could lead to remote code execution when combined with other exploits. The vulnerability arises from improper trust in GCP service account credentials, enabling requests to unauthorized token endpoints. Affected users must be authenticated with repository push permissions, particularly on configurations utilizing GitHub Advanced Security. The issue has been resolved in the latest releases.
Affected Version(s)
Enterprise Server 3.20.0 < 3.20.*
Enterprise Server 3.21.0 < 3.21.*
Enterprise Server 3.22.0 < 3.22.*