Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Enterprise Server — Vulnerabilities & Security Advisories 89

All 89 CVE vulnerabilities found in Enterprise Server, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability disclosures for the vendor's Enterprise Server product, focusing on known software weaknesses and their associated risk tags. It collects a comprehensive history of security advisories and defect reports, covering incidents from the product's initial release through the present day. Readers can use this repository to track the vendor's advisory patterns, analyze specific weakness classes, and review the full vulnerability timeline of this product. The data is organized to support threat modeling and patch management, enabling users to identify recurring fault types and correlate them with specific update cycles. No individual CVE identifiers are listed in this summary; the focus remains on the structural relationship between the vendor, the product, and the nature of the defects. This resource is intended for security teams and infrastructure administrators who need a clear, chronological view of the product's security posture. It facilitates rapid assessment of which vulnerability classes have historically impacted the Enterprise Server and how the vendor responded to each report.

Vendor: GitHub

CVE ID Title CVSS Severity Published
CVE-2026-75101 Authorization bypass vulnerability in GitHub Enterprise Server allowed reading of private pull request diffs and patches via repository name collision CWE-639 6.0 Medium 2026-09-22
CVE-2026-77912 Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed HTML attribute injection via the Markdown rendering pipeline CWE-79 7.4 High 2026-09-22
CVE-2026-77987 GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgery CWE-918 9.3 Critical 2026-09-22
CVE-2026-76851 Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed remote code execution via network access from pre-receive hooks to internal services CWE-918 7.7 High 2026-09-01
CVE-2026-19118 Race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution CWE-367 7.7 High 2026-09-01
CVE-2026-18730 Server-side request forgery vulnerability in GitHub Enterprise Server Manage API leaked a replayable gateway-agent bearer token CWE-918 8.2 High 2026-09-01
CVE-2026-15996 Denial of service vulnerability in GitHub Enterprise Server allowed unauthenticated service disruption via deeply nested request parameters CWE-674 6.6 Medium 2026-08-05
CVE-2026-17556 Path traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance storage via the X-GitHub-Request-Id header CWE-22 8.8 High 2026-08-05
CVE-2026-15783 Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suites CWE-862 - - 2026-07-17
CVE-2026-15343 Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot dependency-file paths CWE-22 - - 2026-07-17
CVE-2026-15007 Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via deeply nested YAML in release notes configuration CWE-770 - - 2026-07-17
CVE-2026-14340 An incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositories CWE-863 - - 2026-07-01
CVE-2026-10585 Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed arbitrary JavaScript execution via crafted Discussion titles in the Q&A category CWE-79 - - 2026-06-30
CVE-2026-9132 Missing authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository contents via the Copilot pull request diff summary endpoint CWE-862 - - 2026-06-30
CVE-2026-9106 UI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organization runner management via undisclosed OAuth scope on consent screen CWE-451 - - 2026-06-30
CVE-2026-9312 Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to internal services via path traversal in upload endpoint CWE-918 - - 2026-05-27
CVE-2026-8606 Server-Side Request Forgery in GitHub Enterprise Server via Advisory Package URL Endpoint CWE-918 - - 2026-05-26
CVE-2026-8106 Reflected HTML injection vulnerability in GitHub Enterprise Server Management Console login page allowed credential theft CWE-79 6.1AI Medium AI 2026-05-07
CVE-2026-8034 Server-side request forgery vulnerability in GitHub Enterprise Server notebook viewer via URL parser confusion CWE-918 8.2AI High AI 2026-05-07
CVE-2026-7541 Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via unauthenticated API endpoint CWE-770 7.5AI High AI 2026-05-07
CVE-2026-6736 Authentication bypass vulnerability in GitHub Enterprise Server allowed creation of local user accounts bypassing the configured external identity provider CWE-306 6.5AI Medium AI 2026-05-07
CVE-2026-5845 Improper authorization fallback allows scoped user-to-server token installation escape in GitHub Enterprise Server CWE-639 8.1AI High AI 2026-04-21
CVE-2026-3307 Authorization bypass in GitHub Enterprise Server secret scanning push protection allows cross-repository modification of delegated bypass reviewers CWE-639 2.7AI Low AI 2026-04-21
CVE-2026-5512 Improper authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository names via mobile upload policy API CWE-201 4.3AI Medium AI 2026-04-21
CVE-2026-4296 Incorrect Regular Expression vulnerability in GitHub Enterprise Server allowed unauthorized access to user accounts via OAuth callback URL validation bypass CWE-185 8.2AI High AI 2026-04-21
CVE-2026-5921 Server-Side Request Forgery in GitHub Enterprise Server allowed extraction of sensitive environment variables via timing side-channel attack CWE-918 7.5AI High AI 2026-04-21
CVE-2026-3582 Incorrect Authorization in GitHub Enterprise Server allows access to issue and commit search results without repo scope CWE-862 6.5AI Medium AI 2026-03-10
CVE-2026-2266 Improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site scripting via task list content and enabled arbitrary HTML injection CWE-79 5.4AI Medium AI 2026-03-10
CVE-2026-3306 Improper authorization in GitHub Projects allows modification of issue and pull request metadata without repository write access CWE-639 4.3AI Medium AI 2026-03-10
CVE-2026-3854 Remote code execution via git push option injection in GitHub Enterprise Server CWE-77 8.8AI High AI 2026-03-10

All 89 known CVE vulnerabilities affecting Enterprise Server with full Chinese analysis, references, and POCs where available.