CVE-2026-9312
A server-side request forgery (SSRF) flaw in GitHub Enterprise Server's upload endpoint lets an unauthenticated attacker inject path‑traversal content to reach internal services and potentially expose sensitive credentials. The issue affects all versions prior to 3.22 and was patched in releases 3.17.17, 3.18.11, 3.19.8, 3.20.4, and 3.21.2.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
GitHub Enterprise Server installations running versions earlier than 3.22 (including 3.21.1).
Real-world impact
An attacker could bypass intended request flows, call internal APIs, and access or leak sensitive data such as credentials.
Why this severity
CVSS v4 base score 9.2 (Critical) reflects network‑attackable, high impact on confidentiality and integrity with no privileges or user interaction required.
What to do about it
- 01Upgrade GitHub Enterprise Server to one of the fixed versions: 3.17.17, 3.18.11, 3.19.8, 3.20.4, or 3.21.2 (or any later version that includes the patch).
NVD-referenced vendor advisory
Timeline
- May 27, 2026 · May 27, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 25, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- docs.github.com/en/enterprise-server@3.17/a…productrelease notes
- docs.github.com/en/enterprise-server@3.18/a…productrelease notes
- docs.github.com/en/enterprise-server@3.19/a…productrelease notes
- docs.github.com/en/enterprise-server@3.20/a…productrelease notes
- docs.github.com/en/enterprise-server@3.21/a…