在 GitHub Enterprise Server 中发现了时间检查与时间使用(Time-of-Check Time-of-Use, TOCTOU)竞争条件漏洞,该漏洞可导致远程代码执行。利用该漏洞需要一个对目标仓库具有写权限的已认证用户,并且需要精确把握并发上传请求的时序。该漏洞影响所有低于 3.22 版本的 GitHub Enterprise Server,并在版本 3.17.20、3.18.14、3.19.11、3.20.7、3.21.5 和 3.22.0 中修复。该漏洞是通过 GitHub 漏洞赏金计划报
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GitHub | Enterprise Server | 3.17.0 ~ 3.17.19 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18730 | 8.2 HIGH | Server-side request forgery vulnerability in GitHub Enterprise Server Manage API leaked a |
| CVE-2026-76851 | 7.7 HIGH | Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed remote code |
No comments yet