An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch of pull requests in private repositories without authorization. Access tokens for raw pull reques
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GitHub | Enterprise Server | 3.17.0 ~ 3.17.* | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77987 | 9.3 CRITICAL | GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgery |
| CVE-2026-77912 | 7.4 HIGH | Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed HTML attribu |
No comments yet