CVE-2026-4296Disclosure(github / enterprise_server)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An incorrect regular expression vulnerability was identified in GitHub Enterprise Server that allowed an attacker to bypass OAuth redirect URI validation. An attacker with knowledge of a first-party OAuth application's registered callback URL could craft a malicious authorization link that, when clicked by a victim, would redirect the OAuth authorization code to an attacker-controlled domain. This could allow the attacker to gain unauthorized access to the victim's account with the scopes granted to the OAuth application. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.20.1, 3.19.5, 3.18.8, 3.17.14, 3.16.17, 3.15.21, 3.14.26. This vulnerability was reported via the GitHub Bug Bounty program.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-185

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_server

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Disclousure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-22); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
enterprise_server

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-22: 1Mentions · 2026-04-26: 1Mentions · 2026-07-22: 1Technical Details · 2026-04-26: 1Technical Details · 2026-07-22: 104-2204-2607-22
Signal classification2 categories
Disclosure
266.7%
Disclousure
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-221
Disclousure1
2026-04-261
Disclosure1
2026-07-221
Disclosure1
Full discourse3 posts
  • Hacktron AI@HacktronAI
    Disclosure

    CVE-2026-4296: We found a bug that could takeover Github repositories through OAuth redirect. https://hackerone.com/reports/3588801

    Post summary

    A new CVE (CVE‑2026‑4296) is disclosed, describing a bug that could allow takeover of GitHub repositories through an OAuth redirect.

    0110140708.8K
    4.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4296 An incorrect regular expression vulnerability was identified in GitHub Enterprise Server that allowed an attacker to bypass OAuth redirect URI validation. An attacker w… https://www.cve.org/CVERecord?id=CVE-2026-4296

    Post summary

    A disclosure of CVE‑2026‑4296, an incorrect regex vulnerability in GitHub Enterprise Server that allows bypass of OAuth redirect URI validation, with no PoC, exploit, patch, or active exploitation details provided.

    00000169
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclousure

    CVE-2026-4296 OAuth Redirect URI Validation Bypass in GitHub Enterprise ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4296 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet merely announces CVE‑2026‑4296, an OAuth redirect URI validation bypass in GitHub Enterprise, linking to a vulnerability detail page and a scanning alert link.

    0000056
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgithubenterprise_server---
Appgithubenterprise_server3.20.0--

Explore more