VendorsGithubenterprise_server3.20.0
Vulnerabilities

Github Enterprise Server 3.20.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2026-5845
Improper authorization fallback allows scoped user-to-server token installation escape in GitHub Enterprise Server
Published 2026-04-21 · Analyzed
9.6EPSS 0.003
CVE-2026-5921
Server-Side Request Forgery in GitHub Enterprise Server allowed extraction of sensitive environment variables via timing side-channel attack
Published 2026-04-21 · Analyzed
8.9EPSS 0.004
CVE-2026-4296
Incorrect Regular Expression vulnerability in GitHub Enterprise Server allowed unauthorized access to user accounts via OAuth callback URL validation bypass
Published 2026-04-21 · Analyzed
8.8EPSS 0.004
CVE-2026-5512
Improper authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository names via mobile upload policy API
Published 2026-04-21 · Analyzed
5.3EPSS 0.003
CVE-2026-3307
Authorization bypass in GitHub Enterprise Server secret scanning push protection allows cross-repository modification of delegated bypass reviewers
Published 2026-04-21 · Analyzed
5.3EPSS 0.003