CVE-2026-9312: Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to internal services via path traversal in upload endpoint
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload endpoint. By injecting path traversal content into request parameters, an attacker could bypass the intended request flow and redirect internal API calls, potentially accessing internal services and exposing sensitive credentials. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.17.17, 3.18.11, 3.19.8, 3.20.4, and 3.21.2. This vulnerability was reported via the GitHub Bug Bounty program.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitHub Enterprise Serverto a version that resolves this vulnerability.Fixed in 3.17.17 - Upgrade
Upgrade
GitHub Enterprise Serverto a version that resolves this vulnerability.Fixed in 3.18.11 - Upgrade
Upgrade
GitHub Enterprise Serverto a version that resolves this vulnerability.Fixed in 3.19.8 - Upgrade
Upgrade
GitHub Enterprise Serverto a version that resolves this vulnerability.Fixed in 3.20.4 - Upgrade
Upgrade
GitHub Enterprise Serverto a version that resolves this vulnerability.Fixed in 3.21.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9312?
CVE-2026-9312 has a critical severity score of 9.2.
How do I fix CVE-2026-9312?
To fix CVE-2026-9312, update GitHub Enterprise Server to the latest version where the vulnerability has been patched.
What type of vulnerability is CVE-2026-9312?
CVE-2026-9312 is classified as a server-side request forgery (SSRF) vulnerability.
What attacks can be performed using CVE-2026-9312?
An attacker can exploit CVE-2026-9312 to send crafted requests to internal services through path traversal in the upload endpoint.
Who is affected by CVE-2026-9312?
Organizations using vulnerable versions of GitHub Enterprise Server are at risk from CVE-2026-9312.