CVE-2026-1999: Server-Side Request Forgery in GitHub Enterprise Server Webhook Delivery Allows Access to Internal Services
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to access internal services bound to loopback or unspecified addresses, potentially disrupting background job processing, accessing administrative endpoints, metrics, and profiling data, or manipulating job queues. Exploitation required an authenticated user with permissions to configure webhooks (repository, organization, or GitHub App administrator privileges). This vulnerability affected all versions of GitHub Enterprise Server prior to 3.20 and was fixed in versions 3.14.22, 3.15.17, 3.16.13, 3.17.10, 3.18.4, and 3.19.1. This vulnerability was reported via the GitHub Bug Bounty program.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1999?
CVE-2026-1999 is classified as a medium severity vulnerability due to its potential to allow unauthorized pull request merges.
How do I fix CVE-2026-1999?
To remediate CVE-2026-1999, upgrade GitHub Enterprise Server to version 3.19.3 or later.
What versions of GitHub Enterprise Server are affected by CVE-2026-1999?
CVE-2026-1999 affects GitHub Enterprise Server versions up to 3.19.2, 3.18.5, and 3.17.11.
What type of vulnerability is CVE-2026-1999?
CVE-2026-1999 is an incorrect authorization vulnerability allowing unauthorized merging of pull requests.
Can CVE-2026-1999 be exploited remotely?
Yes, CVE-2026-1999 can be exploited remotely by an attacker who can manipulate pull requests.