CVE-2026-2266Disclosure(github / enterprise_server)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed DOM-based cross-site scripting via task list content. The task list content extraction logic did not properly re-encode browser-decoded text nodes before rendering, allowing user-supplied HTML to be injected into the page. An authenticated attacker could craft malicious task list items in issues or pull requests to execute arbitrary scripts in the context of another user's browser session. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.20 and was fixed in versions 3.18.6 and 3.19.3. This vulnerability was reported via the GitHub Bug Bounty program.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_server

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-10); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
enterprise_server

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-10: 2Mentions · 2026-03-12: 1Technical Details · 2026-03-10: 203-1003-12
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-102
Disclosure2
2026-03-121
Disclosure1
Full discourse3 posts
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos GitHub ❗ CVE-2026-3854 ❗ CVE-2026-2266 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-github/ https://t.co/NcpmgutiwX

    Post summary

    The tweet announces the existence of two CVEs affecting GitHub products and links to an external resource for more information, without providing PoC, exploit details, or mitigation steps.

    00010143
    6.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-2266 An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed DOM-based cross-site scripting via task list content. The task… https://www.cve.org/CVERecord?id=CVE-2026-2266 ----- Traducción: CVE-2026-2266 Se … http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-2266 as a DOM-based XSS vulnerability in GitHub Enterprise Server, with no exploits, patches, or active exploitation mentioned.

    0000027
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2266 An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed DOM-based cross-site scripting via task list content. The task… https://www.cve.org/CVERecord?id=CVE-2026-2266

    Post summary

    A new CVE-2026-2266 was disclosed describing a DOM‑based XSS flaw in GitHub Enterprise Server via task list content, but no PoC, exploit, or patch information is given.

    00000229
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgithubenterprise_server---

Explore more