VendorsGithubenterprise_serverany version
Vulnerabilities

Github Enterprise Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

117CVEs
CVE-2026-18730
Server-side request forgery vulnerability in GitHub Enterprise Server Manage API leaked a replayable gateway-agent bearer token
Published 2026-09-01 · Modified
8.2EPSS 0.003
CVE-2023-6746
Sensitive Information in Log File in GitHub Enterprise Server
Published 2023-12-21 · Analyzed
8.1EPSS 0.005
CVE-2024-3646
Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Management Console
Published 2024-04-19 · Analyzed
8.0EPSS 0.017
CVE-2024-1354
Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
Published 2024-02-13 · Modified
8.0EPSS 0.017
CVE-2024-2469
Remote Code Execution in GitHub Enterprise Server Allowed Administrators to gain SSH access to the appliance
Published 2024-03-20 · Analyzed
8.0EPSS 0.016
CVE-2024-3684
Improper Privilege Management was identified in GitHub Enterprise Server that allowed privilege escalation in the Management Console
Published 2024-04-19 · Analyzed
8.0EPSS 0.011
CVE-2024-5795
Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed resource exhaustion
Published 2024-07-16 · Modified
7.7EPSS 0.006
CVE-2026-19118
Race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution
Published 2026-09-01 · Analyzed
7.7EPSS 0.005
CVE-2023-23761
Improper authentication vulnerability in GitHub Enterprise Server leading to modification of secret gists
Published 2023-04-07 · Modified
7.7EPSS 0.005
CVE-2024-5746
A Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with the Site Administrator role to gain arbitrary code execution capability on the GitHub Enterprise Server instance. Exploitation required authenticated access to GitHub Enterprise Server as a user with the Site Administrator role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.13 and was fixed in versions 3.12.5, 3.11.11, 3.10.13, and 3.9.16. This vulnerability was reported via the GitHub Bug Bounty program.
Published 2024-06-20 · Analyzed
7.6EPSS 0.009
CVE-2023-6847
Improper Authentication in GitHub Enterprise Server leading to Authentication Bypass for Public Repository Data
Published 2023-12-21 · Modified
7.5EPSS 0.008
CVE-2025-11578
Pre-Receive Hook Path Collision Vulnerability in GitHub Enterprise Server Allowing Privilege Escalation
Published 2025-11-10 · Analyzed
7.5EPSS 0.007
CVE-2026-15996
Denial of service vulnerability in GitHub Enterprise Server allowed unauthenticated service disruption via deeply nested request parameters
Published 2026-08-05 · Analyzed
7.5EPSS 0.004
CVE-2026-7541
Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via unauthenticated API endpoint
Published 2026-05-07 · Analyzed
7.5EPSS 0.004
CVE-2026-2266
Improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site scripting via task list content and enabled arbitrary HTML injection
Published 2026-03-10 · Analyzed
7.4EPSS 0.002
CVE-2025-3509
Pre-Receive Hook Remote Code Execution vulnerability was identified in GitHub Enterprise Server that allowing Privilege Escalation
Published 2025-04-17 · Analyzed
7.2EPSS 0.013
CVE-2022-23741
Incorrect authorization in GitHub Enterprise Server token generation leading to full admin access
Published 2022-12-14 · Modified
7.2EPSS 0.011
CVE-2023-6802
Sensitive Information in Log File in GitHub Enterprise Server
Published 2023-12-21 · Modified
7.2EPSS 0.007
CVE-2024-3470
Repository administrator can bypass organization's ruleset using deploy keys
Published 2024-04-19 · Analyzed
7.2EPSS 0.006
CVE-2023-23764
Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling
Published 2023-07-27 · Modified
7.1EPSS 0.006
CVE-2024-1482
Improper Authorization in GitHub Enterprise Server allowed unauthorized workflow execution
Published 2024-02-14 · Analyzed
7.1EPSS 0.004
CVE-2024-10001
Code Injection Vulnerability in GitHub Enterprise Server Allows Arbitrary Code Execution via Message Handling
Published 2025-01-29 · Analyzed
7.1EPSS 0.004
CVE-2026-1999
Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized merging of pull requests
Published 2026-02-18 · Modified
7.1EPSS 0.003
CVE-2026-8606
Server-Side Request Forgery in GitHub Enterprise Server via Advisory Package URL Endpoint
Published 2026-05-26 · Analyzed
7.0EPSS 0.005
CVE-2025-8447
Incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed read-only access
Published 2025-08-26 · Analyzed
7.0EPSS 0.003
CVE-2023-46649
Race Condition allows Administrative Access on Organization Repositories
Published 2023-12-21 · Modified
7.0EPSS 0.002
CVE-2024-5816
Improper authorization allows persistent access in GitHub Enterprise Server
Published 2024-07-16 · Modified
6.9EPSS 0.005
CVE-2024-6336
Security misconfiguration was identified in GitHub Enterprise Server that allowed sensitive data exposure
Published 2024-07-16 · Modified
6.9EPSS 0.004
CVE-2023-46645
Path traversal in GitHub Enterprise Server leading to arbitrary file reading when building a GitHub Pages site
Published 2023-12-21 · Modified
6.8EPSS 0.008
CVE-2024-5815
Cross Site Request Forgery was identified in GitHub Enterprise Server that allowed write in a user owned repository
Published 2024-07-16 · Modified
6.8EPSS 0.003
CVE-2021-22865
Improper access control in GitHub Enterprise Server leading to unauthorized read access to private repository metadata
Published 2021-04-02 · Modified
6.5EPSS 0.013
CVE-2021-22867
Unsafe configuration options in GitHub Pages leading to path traversal on GitHub Enterprise Server
Published 2021-07-14 · Modified
6.5EPSS 0.012
CVE-2021-22870
Path traversal in GitHub Enterprise Server hosted Pages leads to unauthorized file read access
Published 2021-11-10 · Modified
6.5EPSS 0.011
CVE-2024-1082
Path traversal vulnerability in GitHub Enterprise Server that allowed arbitrary file read with a specially crafted GitHub Pages artifact upload
Published 2024-02-13 · Modified
6.5EPSS 0.008
CVE-2023-23766
Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling
Published 2023-09-22 · Modified
6.5EPSS 0.007
CVE-2022-23737
Improper Privilege Management in GitHub Enterprise Server leading to page creation and deletion
Published 2022-12-01 · Modified
6.5EPSS 0.007
CVE-2024-6337
Incorrect Authorization allows read access to issues in GitHub Enterprise Server
Published 2024-08-20 · Analyzed
6.5EPSS 0.007
CVE-2023-22380
Path traversal in GitHub Enterprise Server leading to arbitrary file reading when building a GitHub Pages site
Published 2023-02-16 · Modified
6.5EPSS 0.007
CVE-2023-23762
Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling
Published 2023-04-07 · Modified
6.5EPSS 0.006
CVE-2023-23765
Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling
Published 2023-08-30 · Modified
6.5EPSS 0.006
← Prev2 / 3Next →