Enterprise server
This hub aggregates every CVE we track for Enterprise server, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
175
CVEs tracked
25
Critical
51
High
0
In CISA KEV
Severity distribution
MEDIUM88HIGH51CRITICAL25LOW5
Monthly trend
2
3
0
2
0
0
3
0
0
2
2
0
0
2
1
1
3
4
5
6
3
4
2
6
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Enterprise server.
- CVE-2026-75101Authorization bypass vulnerability in GitHub Enterprise Server allowed reading of private pull request diffs and patches via repository name collision
- CVE-2026-77912Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed HTML attribute injection via the Markdown rendering pipeline
- CVE-2026-77987GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgery
- CVE-2026-76851Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed remote code execution via network access from pre-receive hooks to internal services8.8
- CVE-2026-19118Race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution7.5
- CVE-2026-18730Server-side request forgery vulnerability in GitHub Enterprise Server Manage API leaked a replayable gateway-agent bearer token7.4
- CVE-2026-15996Denial of service vulnerability in GitHub Enterprise Server allowed unauthenticated service disruption via deeply nested request parameters7.5
- CVE-2026-17556Path traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance storage via the X-GitHub-Request-Id header9.1
- CVE-2026-15783Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suites
- CVE-2026-15343Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot dependency-file paths
- CVE-2026-15007Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via deeply nested YAML in release notes configuration
- CVE-2026-14340An incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositories5.0
- CVE-2026-10585Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed arbitrary JavaScript execution via crafted Discussion titles in the Q&A category5.4
- CVE-2026-9132Missing authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository contents via the Copilot pull request diff summary endpoint6.5
- CVE-2026-9106UI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organization runner management via undisclosed OAuth scope on consent screen5.5
Product normalization is registry-driven with AI assist and human review. How it works