CVE-2026-5921Disclosure(github / enterprise_server)

LOWCVSS 8.9 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to extract sensitive environment variables from the instance through a timing side-channel attack against the notebook rendering service. When private mode was disabled, the notebook viewer followed HTTP redirects without revalidating the destination host, enabling an unauthenticated SSRF to internal services. By chaining this with regex filter queries against an internal API and measuring response time differences, an attacker could infer secret values character by character. Exploitation required that private mode be disabled and that the attacker be able to chain the instance's open redirect endpoint through an external redirect to reach internal services. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.14.26, 3.15.21, 3.16.17, 3.17.14, 3.18.8, 3.19.5, and 3.20.1. This vulnerability was reported via the GitHub Bug Bounty program.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_server

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-04-26)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
enterprise_server

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-22: 1Mentions · 2026-04-26: 2Technical Details · 2026-04-22: 1Technical Details · 2026-04-26: 204-2204-26
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-221
General1
2026-04-262
Disclosure2
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-5921 Server-Side Request Forgery in GitHub Enterprise Server Prior to 3.21 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5921

    Post summary

    The text announces CVE‑2026‑5921, a Server‑Side Request Forgery in GitHub Enterprise Server versions before 3.21, but provides no additional details on exploitability, usage, or mitigation.

    0001057
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5921 A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to extract sensitive environment variables from t… https://www.cve.org/CVERecord?id=CVE-2026-5921

    Post summary

    CVE-2026-5921 is a server‑side request forgery vulnerability in GitHub Enterprise Server that permits attackers to read sensitive environment variables; no exploit, patch, or active exploitation is reported.

    00000181
    57.3K followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-5921: GitHub Enterprise Server SSRF Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04dt3Ws0

    Post summary

    The article announces CVE-2026-5921, an SSRF flaw in GitHub Enterprise Server, and outlines its business impact and recommended response measures.

    0000045
    30 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgithubenterprise_server---
Appgithubenterprise_server3.20.0--

Explore more