---
id: CVE-2026-19118
title: >-
  A time-of-check time-of-use race condition vulnerability was identified in
  GitHub Enterprise Server that allowed remote code execution
summary: >-
  A time-of-check time-of-use race condition vulnerability was identified in
  GitHub Enterprise Server that allowed remote code execution. Exploitation
  required an authenticated user with write access to a repository and precise
  timing of c…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-367
vendor: github
product: enterprise_server
affected:
  - enterprise_server < 3.17.20
  - 'enterprise_server >= 3.18.0, < 3.18.14'
  - 'enterprise_server >= 3.19.0, < 3.19.11'
  - 'enterprise_server >= 3.20.0, < 3.20.7'
  - 'enterprise_server >= 3.21.0, < 3.21.5'
patched:
  - enterprise_server 3.21.5
published: '2026-09-01'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T13:08:54.503'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19118'
references:
  - url: >-
      https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.20
    label: product-cna@github.com
  - url: >-
      https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.14
    label: product-cna@github.com
  - url: >-
      https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.11
    label: product-cna@github.com
  - url: >-
      https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.7
    label: product-cna@github.com
  - url: >-
      https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.5
    label: product-cna@github.com
tags:
  - nvd
epss: 0.00539
epssPercentile: 0.42986
ingestedAt: '2026-09-08T15:33:26.957Z'
---

## Overview

A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution. Exploitation required an authenticated user with write access to a repository and precise timing of concurrent upload requests. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.17.20, 3.18.14, 3.19.11, 3.20.7, and 3.21.5. This vulnerability was reported via the GitHub Bug Bounty program.

## Affected

- `enterprise_server < 3.17.20`
- `enterprise_server >= 3.18.0, < 3.18.14`
- `enterprise_server >= 3.19.0, < 3.19.11`
- `enterprise_server >= 3.20.0, < 3.20.7`
- `enterprise_server >= 3.21.0, < 3.21.5`

## Remediation

Upgrade past the affected range:

- `enterprise_server 3.21.5`
