[CIVN-2026-0441] Multiple Vulnerabilities in GitHub Enterprise Server

By Published On: September 7, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in GitHub Enterprise Server


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


GitHub Enterprise Server versions 3.21.0 to 3.21.4

Overview


Multiple vulnerabilities have been reported in GitHub Enterprise Server, which could allow an attacker to execute arbitrary code, gain unauthorized access to privileged internal services or management credentials and bypass certain email security controls.


Target Audience:

Individuals and organizations using affected versions of GitHub Enterprise Server.


Risk Assessment:

Potential for arbitrary code execution and compromise of privileged GitHub Enterprise Server (GHES) services.


Impact Assessment:

Remote code execution, unauthorized access to privileged internal services or management credentials and bypass certain email security controls.


Description


GitHub Enterprise Server is a self-hosted version of GitHub designed for enterprises to securely manage, develop, and collaborate on code within their own infrastructure.


Multiple vulnerabilities exist in GitHub Enterprise Server due to improper input validation, insufficient network isolation, insecure handling of internal requests, a Time-of-Check Time-of-Use (TOCTOU) race condition in upload processing and a vulnerable SMTP/Postfix configuration.


Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code, gain unauthorized access to privileged internal services or management credentials and bypass certain email security controls.


Solution


Apply appropriate updates as mentioned by the vendor:

https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.5



Vendor Information


GitHub

https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.5


References


GitHub

https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.5


CVE Name

CVE-2026-19118

CVE-2026-18730

CVE-2026-51764

CVE-2026-76851




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqe1soACgkQ3jCgcSdc

ys8Viw/+OBEvk216zWB4RpsTC6vQYEPFdjGv63EKDVpCi4VKh8AObJwM4F3xwTkl

IQAA0mEHG2/8S50hDoWRdRSOzLP3doFZZKiJ6RbOitBJpzVgj05W6s8HVVeIv9Hm

cIlgAS8CFzu5QzPvUHVUeDgfm03zQnQIgxNL/VxyCO5JJa1yV529712eZJYl5dpY

zJJ9i+fHK3m3Shhh1kIcTb9gFnshzbWT4F/8L7YBbAwVNghKjmAqe++g4b5xy+wT

mhgqjrShDBqXYwOEeV8cR3w4XXvNahNNE9XuORNZkeoXYnxPE5iqa/tZqHMDa5w+

Jas6B4ScYlebZIpppxe0p99afGAgdjXIXegeAtvbyK1AEYmLJJPK9xa+qQ9yOW8r

rel76Gk/f+WdQof3A8TF5x/GaH7VidjwVr7NSAG5JW9DMpvVhE13hJZ/nfozGCWf

nunBTWtG37UtKJbggtcYDxxBEqAw+6csotS51x5MgisPUZ5lYuznFQ3WdQAmMM44

b3IWdlU9AOyZN8wZCcbepBjj4ZBmw6ClIGBsRXm9c1xPFd5o06SfXq9Zv879gfvj

LnTuepv12PN8T4lYB06I0Y5T/NvLZZaBB2HE+i3uY0k043JXEj9RwELXBLwkSKE7

+yE+3QBXjlAN8AOeXFtonvnJAtMj5zEefQPMvoYSSB7u0leiYzg=

=N6Au

—–END PGP SIGNATURE—–

Share this article