
[CIVN-2026-0441] Multiple Vulnerabilities in GitHub Enterprise Server
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in GitHub Enterprise Server
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
GitHub Enterprise Server versions 3.21.0 to 3.21.4
Overview
Multiple vulnerabilities have been reported in GitHub Enterprise Server, which could allow an attacker to execute arbitrary code, gain unauthorized access to privileged internal services or management credentials and bypass certain email security controls.
Target Audience:
Individuals and organizations using affected versions of GitHub Enterprise Server.
Risk Assessment:
Potential for arbitrary code execution and compromise of privileged GitHub Enterprise Server (GHES) services.
Impact Assessment:
Remote code execution, unauthorized access to privileged internal services or management credentials and bypass certain email security controls.
Description
GitHub Enterprise Server is a self-hosted version of GitHub designed for enterprises to securely manage, develop, and collaborate on code within their own infrastructure.
Multiple vulnerabilities exist in GitHub Enterprise Server due to improper input validation, insufficient network isolation, insecure handling of internal requests, a Time-of-Check Time-of-Use (TOCTOU) race condition in upload processing and a vulnerable SMTP/Postfix configuration.
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code, gain unauthorized access to privileged internal services or management credentials and bypass certain email security controls.
Solution
Apply appropriate updates as mentioned by the vendor:
https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.5
Vendor Information
GitHub
https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.5
References
GitHub
https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.5
CVE Name
CVE-2026-19118
CVE-2026-18730
CVE-2026-51764
CVE-2026-76851
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqe1soACgkQ3jCgcSdc
ys8Viw/+OBEvk216zWB4RpsTC6vQYEPFdjGv63EKDVpCi4VKh8AObJwM4F3xwTkl
IQAA0mEHG2/8S50hDoWRdRSOzLP3doFZZKiJ6RbOitBJpzVgj05W6s8HVVeIv9Hm
cIlgAS8CFzu5QzPvUHVUeDgfm03zQnQIgxNL/VxyCO5JJa1yV529712eZJYl5dpY
zJJ9i+fHK3m3Shhh1kIcTb9gFnshzbWT4F/8L7YBbAwVNghKjmAqe++g4b5xy+wT
mhgqjrShDBqXYwOEeV8cR3w4XXvNahNNE9XuORNZkeoXYnxPE5iqa/tZqHMDa5w+
Jas6B4ScYlebZIpppxe0p99afGAgdjXIXegeAtvbyK1AEYmLJJPK9xa+qQ9yOW8r
rel76Gk/f+WdQof3A8TF5x/GaH7VidjwVr7NSAG5JW9DMpvVhE13hJZ/nfozGCWf
nunBTWtG37UtKJbggtcYDxxBEqAw+6csotS51x5MgisPUZ5lYuznFQ3WdQAmMM44
b3IWdlU9AOyZN8wZCcbepBjj4ZBmw6ClIGBsRXm9c1xPFd5o06SfXq9Zv879gfvj
LnTuepv12PN8T4lYB06I0Y5T/NvLZZaBB2HE+i3uY0k043JXEj9RwELXBLwkSKE7
+yE+3QBXjlAN8AOeXFtonvnJAtMj5zEefQPMvoYSSB7u0leiYzg=
=N6Au
—–END PGP SIGNATURE—–


