Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-96890— Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed requests to attacker-controlled internal hosts

Quick assessment

Affected
GitHub Enterprise Server
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 GitHub Enterprise Server 中识别出一个服务器端请求伪造(SSRF)漏洞,该漏洞允许仓库贡献者诱导设备向攻击者控制的内部主机发起请求,此漏洞可被链式利用以在设备上实现远程代码执行。针对 GCP 服务账户凭据的秘密扫描验证器未对提交凭据中嵌入的令牌端点目的地进行限制,盲目信任并直接向其发起请求。利用该漏洞需要用户具备身份认证权限,并有权限向启用了 GitHub Advanced Security 和秘密扫描有效性检查的非默认配置实例中的仓库推送内容。此漏洞影响了 GitHub Enterpr

CVSS 8.7 · High

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 3

VendorProduct Version RangeStatus
GitHub Enterprise Server 3.20.0< 3.20.* affected
3.21.0< 3.21.* affected
3.22.0< 3.22.* affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-96890

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed requests to attacker-controlled internal hosts
Source: CVE Program / CVE List V5
Vulnerability Description
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed a repository contributor to cause the appliance to issue requests to attacker-controlled internal hosts, which could be chained to achieve remote code execution on the appliance. The secret scanning validator for GCP service account credentials trusted the token endpoint embedded in a committed credential and issued a request to it without restricting the destination. Exploitation required an authenticated user with permission to push to a repository on an instance with GitHub Advanced Security and secret scanning validity checks enabled, a non-default configuration. This vulnerability affected GitHub Enterprise Server 3.20, 3.21, and 3.22 and was fixed in versions 3.20.9, 3.21.7, and 3.22.2. This vulnerability was reported through the GitHub Bug Bounty program.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
GitHub Enterprise Server 3.20.0 ~ 3.20.* -

II. Public POCs for CVE-2026-96890

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-96890

请登录查看更多情报信息。

Other References for CVE-2026-96890 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-96890

No comments yet


Leave a comment