VendorsGithubenterprise_serverall versions
Vulnerabilities

Github Enterprise Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

121CVEs
CVE-2023-22380
Path traversal in GitHub Enterprise Server leading to arbitrary file reading when building a GitHub Pages site
Published 2023-02-16 · Modified
6.5EPSS 0.007
CVE-2023-23762
Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling
Published 2023-04-07 · Modified
6.5EPSS 0.006
CVE-2023-23765
Incorrect comparison vulnerability in GitHub Enterprise Server leading to commit smuggling
Published 2023-08-30 · Modified
6.5EPSS 0.006
CVE-2024-1908
Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed Privilege Escalation
Published 2024-02-29 · Analyzed
6.5EPSS 0.006
CVE-2022-46258
Incorrect Authorization in GitHub Enterprise Server leads to Action Workflow modifications without Workflow Scope
Published 2023-01-09 · Modified
6.5EPSS 0.006
CVE-2024-5817
Improper authorization allows read access to issue content in GitHub Enterprise Server
Published 2024-07-16 · Modified
6.5EPSS 0.005
CVE-2024-5566
Improper Privilege Management allows for access to unauthorized repository content during migration
Published 2024-07-16 · Modified
6.5EPSS 0.005
CVE-2024-1084
Cross-site Scripting in the tag name pattern field in the tag protections UI in GitHub Enterprise Server allows a malicious website that requires user interaction and social engineering to make changes to a user account via CSP bypass with created CSRF tokens. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12  and was fixed in all versions of 3.11.5, 3.10.7, 3.9.10, and 3.8.15. This vulnerability was reported via the GitHub Bug Bounty program.
Published 2024-02-13 · Modified
6.5EPSS 0.005
CVE-2026-9132
Missing authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository contents via the Copilot pull request diff summary endpoint
Published 2026-06-30 · Analyzed
6.5EPSS 0.004
CVE-2026-6736
Authentication bypass vulnerability in GitHub Enterprise Server allowed creation of local user accounts bypassing the configured external identity provider
Published 2026-05-07 · Analyzed
6.5EPSS 0.004
CVE-2026-1355
Missing Authorization Check in GitHub Enterprise Server Allows Unauthorized Uploads to Repository Migration Exports
Published 2026-02-18 · Analyzed
6.5EPSS 0.004
CVE-2024-10824
Authorization Bypass Vulnerability was Identified in GitHub Enterprise Server that Allowed Unauthorized Internal Users to Access Secret Scanning Alert Data
Published 2024-11-07 · Analyzed
6.5EPSS 0.003
CVE-2023-6804
Improper Privilege Management allows for arbitrary workflows to be run
Published 2023-12-21 · Modified
6.5EPSS 0.002
CVE-2024-6395
GitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Deploy Keys
Published 2024-07-16 · Modified
6.3EPSS 0.005
CVE-2026-10585
Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed arbitrary JavaScript execution via crafted Discussion titles in the Q&A category
Published 2026-06-30 · Analyzed
6.3EPSS 0.003
CVE-2025-6600
GitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Search API
Published 2025-07-01 · Analyzed
6.3EPSS 0.003
CVE-2024-8263
An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty program.
Published 2024-09-23 · Analyzed
6.2EPSS 0.004
CVE-2024-8770
A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attackers to steal sensitive user information via social engineering. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty program.
Published 2024-09-23 · Analyzed
6.1EPSS 0.004
CVE-2026-8106
Reflected HTML injection vulnerability in GitHub Enterprise Server Management Console login page allowed credential theft
Published 2026-05-07 · Analyzed
6.1EPSS 0.003
CVE-2024-2440
Race Condition was identified in GitHub Enterprise Server that allowed maintaining admin permissions
Published 2024-04-19 · Analyzed
5.9EPSS 0.005
CVE-2023-6803
Race Condition allows Unauthorized Outside Collaborator
Published 2023-12-21 · Modified
5.8EPSS 0.002
CVE-2022-23738
Incomplete cache verification issue in GitHub Enterprise Server leading to exposure of private repo files
Published 2022-11-01 · Modified
5.7EPSS 0.007
CVE-2024-9539
An information disclosure vulnerability was identified in GitHub Enterprise Server via attacker uploaded asset URL allowing the attacker to retrieve metadata information of a user who clicks on the URL and further exploit it to create a convincing phishing page. This required the attacker to upload malicious SVG files and phish a victim user to click on that uploaded asset URL. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in versions 3.14.2, 3.13.5, 3.12.10, 3.11.16. This vulnerability was reported via the GitHub Bug Bounty program.
Published 2024-10-11 · Analyzed
5.7EPSS 0.006
CVE-2026-9106
UI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organization runner management via undisclosed OAuth scope on consent screen
Published 2026-06-30 · Analyzed
5.5EPSS 0.004
CVE-2022-23733
Stored XSS vulnerability in GitHub Enterprise Server leading to injection of arbitrary attributes
Published 2022-08-02 · Modified
5.4EPSS 0.006
CVE-2023-23763
Information disclosure in GitHub Enterprise Server leading to private repository leakage
Published 2023-09-01 · Modified
5.3EPSS 0.007
CVE-2023-46646
Improper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via the "Get a check run" API endpoint. This vulnerability did not allow unauthorized access to any repository content besides the name. This vulnerability affected GitHub Enterprise Server version 3.7.0 and above and was fixed in version 3.17.19, 3.8.12, 3.9.7 3.10.4, and 3.11.0.
Published 2023-12-21 · Analyzed
5.3EPSS 0.005
CVE-2026-5512
Improper authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository names via mobile upload policy API
Published 2026-04-21 · Analyzed
5.3EPSS 0.005
CVE-2024-7711
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, and labels of any issue inside a public repository. This was only exploitable inside a public repository. This vulnerability affected GitHub Enterprise Server versions before 3.14 and was fixed in versions 3.13.3, 3.12.8, and 3.11.14. Versions 3.10 of GitHub Enterprise Server are not affected. This vulnerability was reported via the GitHub Bug Bounty program.
Published 2024-08-20 · Analyzed
5.3EPSS 0.005
CVE-2026-3307
Authorization bypass in GitHub Enterprise Server secret scanning push protection allows cross-repository modification of delegated bypass reviewers
Published 2026-04-21 · Analyzed
5.3EPSS 0.005
CVE-2026-14340
An incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositories
Published 2026-07-01 · Analyzed
5.3EPSS 0.004
CVE-2026-3306
Improper authorization in GitHub Projects allows modification of issue and pull request metadata without repository write access
Published 2026-03-10 · Analyzed
5.3EPSS 0.004
CVE-2025-3124
Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized access to private repository names
Published 2025-04-17 · Analyzed
5.3EPSS 0.004
CVE-2026-3582
Incorrect Authorization in GitHub Enterprise Server allows access to issue and commit search results without repo scope
Published 2026-03-10 · Analyzed
5.3EPSS 0.004
CVE-2025-6981
Incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized read-only access
Published 2025-07-15 · Analyzed
5.3EPSS 0.003
CVE-2023-51379
Incorrect Authorization for Issue Comments in GitHub Enterprise Server
Published 2023-12-21 · Analyzed
4.9EPSS 0.006
CVE-2021-22868
Unsafe configuration options in GitHub Pages leading to path traversal on GitHub Enterprise Server
Published 2021-09-24 · Modified
4.3EPSS 0.009
CVE-2022-46257
Information disclosure in GitHub Enterprise Server leading to unauthorized viewing of private repository names
Published 2023-03-07 · Modified
4.3EPSS 0.006
CVE-2023-51380
Incorrect Authorization allows Read Access to Issue Comments in GitHub Enterprise Server
Published 2023-12-21 · Analyzed
4.3EPSS 0.005
CVE-2024-2748
CSRF vulnerability was identified in GitHub Enterprise Server that allowed performing actions on behalf of a user
Published 2024-03-20 · Analyzed
4.3EPSS 0.002
← Prev3 / 4Next →