Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

SSRF vulnerability in GitHub Enterprise Server Management API

An unauthenticated server-side request forgery vulnerability in GitHub Enterprise Server allowed attackers to cause the Manage API to send crafted outbound requests. The vulnerability affected all versions prior to 3.22 and was fixed in versions 3.17.19, 3.18.13, 3.19.10, 3.20.6, and 3.21.4.

Disclosed 2 September 2026 · Record updated 13 September 2026

Impact

Unauthenticated attackers could cause the Manage API to send crafted outbound requests to attacker-controlled hosts and potentially replay HMAC tokens against privileged management agent endpoints.

Our coverage

No articles linked to this incident yet.

Sources

  1. github.comhttps://github.com/advisories/GHSA-xh7g-7v3x-h73p
  2. github.comhttps://github.com/advisories/GHSA-r64m-65x5-h3wx
  3. github.comhttps://github.com/advisories/GHSA-8qwj-prhm-6mp3