Enterprise server
This hub aggregates every CVE we track for Enterprise server, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
164
CVEs tracked
24
Critical
47
High
0
In CISA KEV
Severity distribution
MEDIUM88HIGH47CRITICAL24LOW5
Monthly trend
2
2
3
0
2
0
0
3
0
0
2
2
0
0
2
1
1
3
4
5
6
3
1
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Enterprise server.
- CVE-2026-14340An incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositories5.0
- CVE-2026-10585Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed arbitrary JavaScript execution via crafted Discussion titles in the Q&A category5.4
- CVE-2026-9132Missing authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository contents via the Copilot pull request diff summary endpoint6.5
- CVE-2026-9106UI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organization runner management via undisclosed OAuth scope on consent screen5.5
- CVE-2026-9312Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to internal services via path traversal in upload endpoint8.2
- CVE-2026-8606Server-Side Request Forgery in GitHub Enterprise Server via Advisory Package URL Endpoint5.9
- CVE-2026-8106Reflected HTML injection vulnerability in GitHub Enterprise Server Management Console login page allowed credential theft6.1
- CVE-2026-8034Server-side request forgery vulnerability in GitHub Enterprise Server notebook viewer via URL parser confusion9.8
- CVE-2026-7541Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via unauthenticated API endpoint7.5
- CVE-2026-6736Authentication bypass vulnerability in GitHub Enterprise Server allowed creation of local user accounts bypassing the configured external identity provider6.5
- CVE-2026-5845Improper authorization fallback allows scoped user-to-server token installation escape in GitHub Enterprise Server9.6
- CVE-2026-3307Authorization bypass in GitHub Enterprise Server secret scanning push protection allows cross-repository modification of delegated bypass reviewers2.7
- CVE-2026-5512Improper authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository names via mobile upload policy API4.3
- CVE-2026-4296Incorrect Regular Expression vulnerability in GitHub Enterprise Server allowed unauthorized access to user accounts via OAuth callback URL validation bypass8.8
- CVE-2026-5921Server-Side Request Forgery in GitHub Enterprise Server allowed extraction of sensitive environment variables via timing side-channel attack8.9
Product normalization is registry-driven with AI assist and human review. How it works