• PATCH AVAILABLE

CVE-2026-77987: pre-auth remote code execution in GitHub Enterprise Server

Attackers can abuse an SSRF weakness in GitHub Enterprise Server to probe internal services, recover secrets by observing response timing, and then use those secrets to trigger remote code execution on the appliance; this issue is catalogued as CVE-2026-77987. Versions 3.17 through 3.22 are impacted. Successful exploitation requires network reachability to the instance; when private mode is turned off the exploit can be carried out without any account, while with private mode enabled any authenticated user can carry out the attack.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 4.0
9.3CRITICAL
EPSS
0.00891
CWE
CWE-918
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this flaw can enable unauthenticated RCE when private mode is off, so treat systems exposed to untrusted networks as high priority for patching. Install the vendor fixes for affected 3.17–3.22 branches now or block access to the appliance until patched.

What is CVE-2026-77987?

Attackers can abuse an SSRF weakness in GitHub Enterprise Server to probe internal services, recover secrets by observing response timing, and then use those secrets to trigger remote code execution on the appliance; this issue is catalogued as CVE-2026-77987. Versions 3.17 through 3.22 are impacted. Successful exploitation requires network reachability to the instance; when private mode is turned off the exploit can be carried out without any account, while with private mode enabled any authenticated user can carry out the attack. The weakness is classified as CWE-918 (Server-Side Request Forgery).

Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Which versions of GitHub Enterprise Server are affected?

BRANCHAFFECTEDFIXED
3.x3.17.0 – before 3.17.*3.17.*
3.x3.18.0 – before 3.18.*3.18.*
3.x3.19.0 – before 3.19.*3.19.*
3.x3.20.0 – before 3.20.*3.20.*
3.x3.21.0 – before 3.21.*3.21.*
3.x3.22.0 – before 3.22.*3.22.*

Is CVE-2026-77987 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-77987

  1. Upgrade GitHub Enterprise Server to the vendor fixed releases for your 3.17–3.22 branch.
  2. If patching is delayed, restrict network access to the appliance so untrusted hosts cannot reach internal ports.
  3. Rotate instance secrets that might have been exposed and inspect logs for internal requests and timing-based probes.
  4. Follow GitHub's advisory and apply any additional configuration guidance the vendor provides.

Frequently asked questions

Is CVE-2026-77987 being actively exploited?

There are no public reports of exploitation as of 2026-09-30.

Which GitHub Enterprise Server versions are affected by CVE-2026-77987?

GitHub Enterprise Server releases in the 3.17 through 3.22 series are affected.

Is there a patch for CVE-2026-77987?

Yes; GitHub published fixes for the affected 3.17–3.22 branches—upgrade to the vendor's patched releases for your branch.

Does CVE-2026-77987 require authentication?

The vulnerability requires network access and is unauthenticated when private mode is disabled; if private mode is enabled any authenticated user can exploit it.

References