CVE-2026-9312High· 8.2▾ TwilightA server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.1 · likelihood 1.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
6.6%
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload endpoint. By injecting path traversal content into request parameters, an attacker could bypass the intended request flow and redirect internal API calls, potentially accessing internal services and exposing sensitive credentials. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.17.17, 3.18.11, 3.19.8, 3.20.4, and 3.21.2. This vulnerability was reported via the GitHub Bug Bounty program.
enterprise_server >= 3.16.0, < 3.16.19enterprise_server >= 3.17.0, < 3.17.16enterprise_server >= 3.18.0, < 3.18.10enterprise_server >= 3.19.0, < 3.19.7enterprise_server >= 3.20.0, < 3.20.3enterprise_server = 3.21.1Upgrade past the affected range:
enterprise_server 3.20.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-18730High· 7.4A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send crafted outbound requests to an attacker-controlled host
CVE-2026-76851High· 8.8A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance
CVE-2025-68616High· 7.5WeasyPrint helps web developers to create PDF documents
CVE-2026-19118High· 7.5A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution
CVE-2026-12992High· 7.4A flaw was found in Apicurio Registry
CVE-2021-21985Critical· 9.8The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server