CVE-2026-9312Patch(github / enterprise_server)

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch github enterprise_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload endpoint. By injecting path traversal content into request parameters, an attacker could bypass the intended request flow and redirect internal API calls, potentially accessing internal services and exposing sensitive credentials. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.17.17, 3.18.11, 3.19.8, 3.20.4, and 3.21.2. This vulnerability was reported via the GitHub Bug Bounty program.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_server

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 9 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 4 mentions (2026-05-27); latest day: 1
  • 10 total mentions across 5 days

Affected systems

Vendors
Products
enterprise_server

1 version affected across 1 product

Deep dive

Activity timeline10 mentions / 5d
01234Mentions · 2026-05-27: 4Mentions · 2026-05-28: 1Mentions · 2026-05-29: 3Mentions · 2026-06-15: 1Mentions · 2026-07-28: 1Patch / Workaround · 2026-05-27: 3Patch / Workaround · 2026-05-28: 1Patch / Workaround · 2026-05-29: 3Patch / Workaround · 2026-07-28: 1Technical Details · 2026-05-27: 3Technical Details · 2026-05-28: 1Technical Details · 2026-05-29: 3Technical Details · 2026-06-15: 1Technical Details · 2026-07-28: 105-2705-2805-2906-1507-28
Signal classification3 categories
Patch
770.0%
Disclosure
220.0%
General
110.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-05-274
Disclosure1Patch3
2026-05-281
Patch1
2026-05-293
Patch3
2026-06-151
General1
2026-07-281
Disclosure1
Full discourse10 posts
  • Gray Hats@the_yellow_fall
    Patch

    GitHub patches critical GitHub Enterprise Server vulnerabilities (CVE-2026-9312). Learn about key rotation and critical SSRF fixes. #Cybersecurity #GitHub #Infosec #SecurityPatch #SSRF #GHES https://securityonline.info/github-enterprise-server-vulnerabilities/ https://t.co/RerING0XJ7

    Post summary

    GitHub released patches for CVE-2026-9312 on its Enterprise Server, focusing on key rotation and critical SSRF fixes.

    10031624
    12.5K followersView on X
  • DFIR Lab@DFIR_Lab
    Disclosure

    🚨 HIGH SEVERITY: CVE-2026-9312 (CVSS 8.2) SSRF vulnerability in GitHub Enterprise Server allows unauthenticated attackers to access internal services & expose credentials via path traversal. Affected: All versions <3.22 Patched: 3.17.17, 3.18.11, 3.19.8, 3.20.4, 3.21.2 https://t.co/VNrXyoibOq

    Post summary

    GitHub Enterprise Server CVE-2026-9312, a high‑severity SSRF with path traversal that exposes credentials, disclosed with affected versions and several patched releases.

    0001047
    97 followersView on X
  • AI事故観測局@AI_Crash_Watch
    Patch

    【AI事故観測局】 GitHub Enterprise ServerにSSRF脆弱性(CVE-2026-9312)。任意URLへ飛ばされると内部情報に触れる恐れ。影響確認と最新版更新を先に。まず権限を絞ろう。監査も。急いで。 社内の影響確認は済んでる? #セキュリティ #SSRF

    Post summary

    The text is an advisory for GitHub Enterprise Server's SSRF vulnerability (CVE-2026-9312), recommending impact assessment and updating to the latest version, along with permission restrictions and audit. No exploitation evidence or PoC is mentioned.

    00010112
    11 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical SSRF in GitHub Enterprise Server (CVE-2026-9312) A server-side request forgery (SSRF) vulnerability in GitHub Enterprise Server allows an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload endpoint. Attackers can use path traversal to bypass restrictions and redirect internal API calls, potentially accessing sensitive internal services and exposing credentials. 👉Affected: GitHub Enterprise Server < 3.16.20, < 3.17.17, < 3.18.11, < 3.19.8, < 3.20.4, < 3.21.1

    Post summary

    GitHub Enterprise Server is vulnerable to a critical SSRF (CVE-2026-9312) that allows unauthenticated attackers to craft requests to internal services via an upload endpoint with insufficient input validation. No PoC, exploit code, or active exploitation details are included.

    00010122
    196 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-9312: GitHub Enterprise Server SSRF Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04lnJb30

    Post summary

    The text references CVE-2026-9312 as a GitHub Enterprise Server SSRF vulnerability and suggests it includes business impact and response guidance, but offers no concrete PoC, exploit tool, active exploitation reports, or patch details.

    0000032
    31 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Patch

    🚨 #GitHub Enterprise Under Fire: Critical SSRF Flaw (#CVE-2026-9312) Demands Immediate Patch Rotation – Here's How to Secure Your Instance https://undercodetesting.com/github-enterprise-under-fire-critical-ssrf-flaw-cve-2026-9312-demands-immediate-patch-rotation-heres-how-to-secure-your-instance/ Educational Purposes!

    Post summary

    The post announces the new GitHub Enterprise SSRF flaw (CVE‑2026‑9312) and urges users to apply the vendor’s patch or rotate to mitigate the risk, highlighting the importance of immediate update actions.

    0000062
    582 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    GitHubがGHES 3.20.3をリリース-事前認証SSRFが可能な脆弱性を修正-CVE-2026-9312 https://rocket-boys.co.jp/security-measures-lab/github-ghes-ssrf-vulnerability-cve-2026-9312/ #セキュリティ対策Lab #security #securitynews

    Post summary

    GitHub released GHES 3.20.3 to patch a pre‑authentication SSRF vulnerability identified as CVE-2026-9312.

    00000120
    408 followersView on X
  • Mr.Rabbit@01ra66it
    Patch

    【GitHub Enterprise Serverにクリティカル脆弱性】 GitHub Enterprise Serverに複数の脆弱性が確認され、クリティカルを含む修正版が公開されました。特に CVE-2026-9312 は、アップロードエンドポイントの入力検証不備に起因する未認証SSRFです。 攻撃者は細工したリクエストにより、GHESインスタンスから内部サービスへリクエストを送信させ、機密性の高い認証情報や構成情報に影響を及ぼす可能性があります。GHESはソースコード、CI/CD、シークレット管理、内部開発プロセスに近い位置にあるため、侵害時の影響は大きくなります。 利用組織は、修正版への更新、GPG公開キーのローテーション、GHESから内部サービスへの異常通信、監査ログの確認を進めるべきです。日本企業では、開発基盤を通常のWebサーバ以上に高価値資産として扱う必要があります。 #サイバーセキュリティ #GitHubEnterpriseServer #GHES #SSRF #CVE #DevSecOps #脆弱性管理 https://www.security-next.com/185038

    Post summary

    The post reports a critical vulnerability in GitHub Enterprise Server (CVE-2026-9312) and urges users to apply the available patch and follow mitigation steps, providing technical details of the SSRF flaw.

    00000242
    3.7K followersView on X
  • ADK Cyber@ADKCyber
    Patch

    CVE-2026-9312 (CVSS 9.2) is a high-severity vulnerability in GitHub Enterprise Server. Organizations using the product should check for available updates and apply them. https://nvd.nist.gov/vuln/detail/CVE-2026-9312 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/MzIYgwA1WQ

    Post summary

    The tweet highlights a high‑severity CVE for GitHub Enterprise Server and urges users to apply available updates, with no detailed technical or exploit information provided.

    0000053
    81 followersView on X
  • ThreadLinqs@threadlinqs
    Patch

    NEW THREAT INTEL: GHES 3.20.3 patches pre-auth SSRF CVE-2026-9312 (CVSS 9.6) + Dirty Frag kernel LPEs. https://intel.threadlinqs.com/threat/TL-2026-0605 #ThreatIntel #CyberSecurity #GitHub https://t.co/osxVssX5dP

    Post summary

    GitHub Enterprise Server 3.20.3 now includes a patch for the high‑severity CVE‑2026‑9312 SSRF vulnerability and addresses Dirty Frag kernel LPE issues.

    0000066
    51 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgithubenterprise_server---
Appgithubenterprise_server3.21.1--

Explore more