SSRF vulnerability in GitHub Enterprise Server Management API
An unauthenticated server-side request forgery vulnerability in GitHub Enterprise Server allowed attackers to cause the Manage API to send crafted outbound requests. The vulnerability affected all versions prior to 3.22 and was fixed in versions 3.17.19, 3.18.13, 3.19.10, 3.20.6, and 3.21.4.
Disclosed 2 September 2026 · Record updated 13 September 2026
Impact
Unauthenticated attackers could cause the Manage API to send crafted outbound requests to attacker-controlled hosts and potentially replay HMAC tokens against privileged management agent endpoints.
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-xh7g-7v3x-h73p
- github.comhttps://github.com/advisories/GHSA-r64m-65x5-h3wx
- github.comhttps://github.com/advisories/GHSA-8qwj-prhm-6mp3
