Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN929
_____________________________________________________________________

DATE                : 24/09/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S):  Systems running GitHub Enterprise Server
                 versions prior to 3.22.1, 3.21.6, 3.20.8, 3.19.12,
                               3.18.15, and 3.17.21.
  
=====================================================================
https://github.com/advisories/GHSA-5p5v-w43x-q8v7
https://github.com/advisories/GHSA-xh7g-7v3x-h73p
https://github.com/advisories/GHSA-6293-4rx2-2p57
https://github.com/advisories/GHSA-843p-hf47-6r9f
_____________________________________________________________________


A server-side request forgery (SSRF) vulnerability was...
Critical severity
Unreviewed 

Package
No package listed— Suggest a package

Affected versions
Unknown

Patched versions
Unknown


Description

A server-side request forgery (SSRF) vulnerability was identified in
the notebook viewer of GitHub Enterprise Server. The notebook viewer
validated the scheme and host of a user-supplied URL but did not
validate the port, allowing requests to be directed to internal
services listening on other ports of the same appliance. Response
bodies were not returned to the requester, but response timing acted
as an oracle that allowed instance secrets to be extracted character
by character. An extracted secret could then be used in a separate
interaction with an internal service to obtain remote code execution
on the appliance. Exploitation required network access to the
instance and was unauthenticated when private mode was disabled,
or required any authenticated user when private mode was enabled.
This vulnerability affected GitHub Enterprise Server versions 3.17
through 3.22 and was fixed in versions 3.22.1, 3.21.6, 3.20.8,
3.19.12, 3.18.15, and 3.17.21. This vulnerability was reported
through the GitHub Bug Bounty program.


References

    https://nvd.nist.gov/vuln/detail/CVE-2026-77987
    https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.21
    https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.15
    https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.12
    https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.8
    https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.6
    https://docs.github.com/en/enterprise-server@3.22/admin/release-notes#3.22.1


Severity
Critical
9.3/ 10

CVSS v4 base metrics
Exploitability Metrics
Attack Vector Network
Attack Complexity Low
Attack Requirements None
Privileges Required None
User interaction None
Vulnerable System Impact Metrics
Confidentiality High
Integrity High
Availability High
Subsequent System Impact Metrics
Confidentiality None
Integrity None
Availability None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS score
0.891% (58th percentile)

Weaknesses
Weakness CWE-208

CVE ID
CVE-2026-77987

GHSA ID
GHSA-5p5v-w43x-q8v7

Source code
No known source code

_____________________________________________________________________

A server-side request forgery (SSRF) vulnerability was...
High severity Unreviewed Published 3 weeks ago to the GitHub Advisory
Database 

Package
No package listed— Suggest a package

Affected versions
Unknown

Patched versions
Unknown


Description

A server-side request forgery (SSRF) vulnerability was identified
in GitHub Enterprise Server that allowed an unauthenticated attacker
to cause the Manage API to send crafted outbound requests to an
attacker-controlled host. An unauthenticated endpoint parsed an
attacker-supplied cluster configuration and issued gateway-to-agent
requests whose HMAC authenticated only a timestamp, not the request
path or body. An attacker positioned to intercept the outbound request
could capture this token and replay it against privileged management
agent endpoints. High-availability deployments were not affected due
to a topology restriction. This vulnerability affected all versions
of GitHub Enterprise Server prior to 3.22 and was fixed in versions
3.17.19, 3.18.13, 3.19.10, 3.20.6, and 3.21.4. This vulnerability
was reported via the GitHub Bug Bounty program.


References

    https://nvd.nist.gov/vuln/detail/CVE-2026-18730
    https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.19
    https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.13
    https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.10
    https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.6
    https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.4
    https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.21
    https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.15
    https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.12
    https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.8
    https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.6


Severity
High
8.2/ 10

CVSS v4 base metrics
Exploitability Metrics
Attack Vector Network
Attack Complexity Low
Attack Requirements Present
Privileges Required None
User interaction None
Vulnerable System Impact Metrics
Confidentiality High
Integrity None
Availability None
Subsequent System Impact Metrics
Confidentiality None
Integrity None
Availability None
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X


EPSS score
0.291%(22nd percentile)

Weaknesses
Weakness CWE-918

CVE ID
CVE-2026-18730

GHSA ID
GHSA-xh7g-7v3x-h73p

Source code
No known source code
_____________________________________________________________________


A stored cross-site scripting (XSS) vulnerability was...
High severity Unreviewed 

Package
No package listed— Suggest a package

Affected versions
Unknown

Patched versions
Unknown


Description

A stored cross-site scripting (XSS) vulnerability was identified in
GitHub Enterprise Server that allowed an authenticated attacker to
inject arbitrary HTML attributes into rendered Markdown because the
Markdown rendering pipeline rewrote quote characters in already-sanitized
HTML without re-sanitizing the result. Crafted Markdown could abuse
same-origin JavaScript gadgets to bypass Content Security Policy and
gain control of the page DOM when viewed by another user. Successful
exploitation could allow an attacker to read content visible to the
victim, extract embedded CSRF tokens, perform state-changing actions
as the victim, and exfiltrate data through same-origin writes. The
payload could also propagate to repositories and organizations where
the victim had write access. This vulnerability affected supported
GitHub Enterprise Server releases in the 3.17, 3.18, 3.19, 3.20,
3.21, and 3.22 series and was fixed in versions 3.22.1, 3.21.6,
3.20.8, 3.19.12, 3.18.15, and 3.17.21. This vulnerability was
reported via the GitHub Bug Bounty program.


References

    https://nvd.nist.gov/vuln/detail/CVE-2026-77912
    https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.21
    https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.15
    https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.12
    https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.8
    https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.6
    https://docs.github.com/en/enterprise-server@3.22/admin/release-notes#3.22.1


Severity
High
7.4/ 10

CVSS v4 base metrics
Exploitability Metrics
Attack Vector Network
Attack Complexity High
Attack Requirements None
Privileges Required Low
User interaction Passive
Vulnerable System Impact Metrics
Confidentiality High
Integrity High
Availability None
Subsequent System Impact Metrics
Confidentiality Low
Integrity Low
Availability None
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:X

EPSS score
0.45(39th percentile)

Weaknesses
Weakness CWE-79

CVE ID
CVE-2026-77912

GHSA ID
GHSA-6293-4rx2-2p57

Source code
No known source code 

_____________________________________________________________________

An authorization bypass vulnerability was identified in...
Moderate severity Unreviewed 

Package
No package listed— Suggest a package

Affected versions
Unknown

Patched versions
Unknown


Description

An authorization bypass vulnerability was identified in GitHub
Enterprise Server that allowed any authenticated user of the
instance to read the raw diff or patch of pull requests in private
repositories without authorization. Access tokens for raw pull
request diffs and patches were scoped to the repository name and
pull request number rather than to a globally unique repository
identifier, so an attacker who created a repository and pull request
matching a target's repository name and pull request number could
use a token for their own repository to retrieve the private pull
request's contents. Exploitation required the attacker to know the
target repository's name and a valid pull request number. This
vulnerability affected all versions of GitHub Enterprise Server
prior to 3.22 and was fixed in versions 3.17.21, 3.18.15, 3.19.12,
3.20.8, and 3.21.6. This vulnerability was reported via the
GitHub Bug Bounty program.


References

    https://nvd.nist.gov/vuln/detail/CVE-2026-75101
    https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.21
    https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.15
    https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.12
    https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.8
    https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.6


Severity
Moderate
6.0/ 10

CVSS v4 base metrics
Exploitability Metrics
Attack Vector Network
Attack Complexity Low
Attack Requirements Present
Privileges Required Low
User interaction None
Vulnerable System Impact Metrics
Confidentiality High
Integrity None
Availability None
Subsequent System Impact Metrics
Confidentiality None
Integrity None
Availability None
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X


EPSS score
0.449% (38th percentile)

Weaknesses
Weakness CWE-639

CVE ID
CVE-2026-75101

GHSA ID
GHSA-843p-hf47-6r9f

Source code
No known source code


=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




