| cvss | 9.8receipt- Source
- NVD
- Its words
9.8- Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore- Said since
- 2026-10-03 00:06 UTC
- Last answered
- 2026-10-04 18:16 UTC
- Original
- open at the source
| 2026-10-03 00:06 UTC | 9.8 | | 2026-09-29 09:45 UTC | — |
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unknown",
"product": "Enterprise Server",
"vendor": "GitHub",
"versions": [
{
"changes": [
{
"at": "3.17.21",
"status": "unaffected"
}
],
"lessThan": "3.17.*",
"status": "affected",
"version": "3.17.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.18.15",
"status": "unaffected"
}
],
"lessThan": "3.18.*",
"status": "affected",
"version": "3.18.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.19.12",
"status": "unaffected"
}
],
"lessThan": "3.19.*",
"status": "affected",
"version": "3.19.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.20.8",
"status": "unaffected"
}
],
"lessThan": "3.20.*",
"status": "affected",
"version": "3.20.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.21.6",
"status": "unaffected"
}
],
"lessThan": "3.21.*",
"status": "affected",
"version": "3.21.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.22.1",
"status": "unaffected"
}
],
"lessThan": "3.22.*",
"status": "affected",
"version": "3.22.0",
"versionType": "semver"
}
]
}
],
"source": "product-cna@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E83141CB-1932-42B9-9425-48416C63A613",
"versionEndExcluding": "3.17.21",
"versionStartIncluding": "3.17.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "15CAF100-6E9B-4729-B9CB-9DC9A28476EE",
"versionEndExcluding": "3.18.15",
"versionStartIncluding": "3.18.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "1C9673F5-F19A-48A0-B9E9-C75E506A14E9",
"versionEndExcluding": "3.19.12",
"versionStartIncluding": "3.19.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "DCA88B70-765F-4318-82A3-67060A58BC31",
"versionEndExcluding": "3.20.8",
"versionStartIncluding": "3.20.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3E0F487F-1EC6-412C-BFC3-29FE2D88886E",
"versionEndExcluding": "3.21.6",
"versionStartIncluding": "3.21.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "78D23030-388E-448B-9C3D-3F89FA946F96",
"versionEndExcluding": "3.22.1",
"versionStartIncluding": "3.22.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the port, allowing requests to be directed to internal services listening on other ports of the same appliance. Response bodies were not returned to the requester, but response timing acted as an oracle that allowed instance secrets to be extracted character by character. An extracted secret could then be used in a separate interaction with an internal service to obtain remote code execution on the appliance. Exploitation required network access to the instance and was unauthenticated when private mode was disabled, or required any authenticated user when private mode was enabled. This vulnerability affected GitHub Enterprise Server versions 3.17 through 3.22 and was fixed in versions 3.22.1, 3.21.6, 3.20.8, 3.19.12, 3.18.15, and 3.17.21. This vulnerability was reported through the GitHub Bug Bounty program."
}
],
"id": "CVE-2026-77987",
"lastModified": "2026-10-02T18:37:45.130",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"cvssMetricV40": [
{
"cvssData": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"availabilityRequirement": "NOT_DEFINED",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"confidentialityRequirement": "NOT_DEFINED",
"exploitMaturity": "NOT_DEFINED",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"source": "product-cna@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-77987",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T15:26:50.899891Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-22T21:17:32.653",
"references": [
{
"source": "product-cna@github.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.21"
},
{
"source": "product-cna@github.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.15"
},
{
"source": "product-cna@github.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.12"
},
{
"source": "product-cna@github.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.8"
},
{
"source": "product-cna@github.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.6"
},
{
"source": "product-cna@github.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://docs.github.com/en/enterprise-server@3.22/admin/release-notes#3.22.1"
}
],
"sourceIdentifier": "product-cna@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-208"
},
{
"lang": "en",
"value": "CWE-918"
}
],
"source": "product-cna@github.com",
"type": "Secondary"
}
]
}
} |
|---|
| product | Enterprise Serverreceipt- Source
- NVD
- Its words
Enterprise Server- Read by
field:cve.affected[].affectedData[].product- Said since
- 2026-09-29 17:49 UTC
- Last answered
- 2026-10-04 18:16 UTC
- Original
- open at the source
| 2026-09-29 17:49 UTC | Enterprise Server | | 2026-09-29 09:45 UTC | — |
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unknown",
"product": "Enterprise Server",
"vendor": "GitHub",
"versions": [
{
"changes": [
{
"at": "3.17.21",
"status": "unaffected"
}
],
"lessThan": "3.17.*",
"status": "affected",
"version": "3.17.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.18.15",
"status": "unaffected"
}
],
"lessThan": "3.18.*",
"status": "affected",
"version": "3.18.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.19.12",
"status": "unaffected"
}
],
"lessThan": "3.19.*",
"status": "affected",
"version": "3.19.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.20.8",
"status": "unaffected"
}
],
"lessThan": "3.20.*",
"status": "affected",
"version": "3.20.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.21.6",
"status": "unaffected"
}
],
"lessThan": "3.21.*",
"status": "affected",
"version": "3.21.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.22.1",
"status": "unaffected"
}
],
"lessThan": "3.22.*",
"status": "affected",
"version": "3.22.0",
"versionType": "semver"
}
]
}
],
"source": "product-cna@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E83141CB-1932-42B9-9425-48416C63A613",
"versionEndExcluding": "3.17.21",
"versionStartIncluding": "3.17.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "15CAF100-6E9B-4729-B9CB-9DC9A28476EE",
"versionEndExcluding": "3.18.15",
"versionStartIncluding": "3.18.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "1C9673F5-F19A-48A0-B9E9-C75E506A14E9",
"versionEndExcluding": "3.19.12",
"versionStartIncluding": "3.19.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "DCA88B70-765F-4318-82A3-67060A58BC31",
"versionEndExcluding": "3.20.8",
"versionStartIncluding": "3.20.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3E0F487F-1EC6-412C-BFC3-29FE2D88886E",
"versionEndExcluding": "3.21.6",
"versionStartIncluding": "3.21.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "78D23030-388E-448B-9C3D-3F89FA946F96",
"versionEndExcluding": "3.22.1",
"versionStartIncluding": "3.22.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the port, allowing requests to be directed to internal services listening on other ports of the same appliance. Response bodies were not returned to the requester, but response timing acted as an oracle that allowed instance secrets to be extracted character by character. An extracted secret could then be used in a separate interaction with an internal service to obtain remote code execution on the appliance. Exploitation required network access to the instance and was unauthenticated when private mode was disabled, or required any authenticated user when private mode was enabled. This vulnerability affected GitHub Enterprise Server versions 3.17 through 3.22 and was fixed in versions 3.22.1, 3.21.6, 3.20.8, 3.19.12, 3.18.15, and 3.17.21. This vulnerability was reported through the GitHub Bug Bounty program."
}
],
"id": "CVE-2026-77987",
"lastModified": "2026-10-02T18:37:45.130",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"cvssMetricV40": [
{
"cvssData": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"availabilityRequirement": "NOT_DEFINED",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"confidentialityRequirement": "NOT_DEFINED",
"exploitMaturity": "NOT_DEFINED",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"source": "product-cna@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-77987",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T15:26:50.899891Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-22T21:17:32.653",
"references": [
{
"source": "product-cna@github.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.21"
},
{
"source": "product-cna@github.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.15"
},
{
"source": "product-cna@github.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.12"
},
{
"source": "product-cna@github.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.8"
},
{
"source": "product-cna@github.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.6"
},
{
"source": "product-cna@github.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://docs.github.com/en/enterprise-server@3.22/admin/release-notes#3.22.1"
}
],
"sourceIdentifier": "product-cna@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-208"
},
{
"lang": "en",
"value": "CWE-918"
}
],
"source": "product-cna@github.com",
"type": "Secondary"
}
]
}
} |
|---|
| status | Analyzedreceipt- Source
- NVD
- Its words
Analyzed- Read by
field:cve.vulnStatus- Said since
- 2026-10-03 00:06 UTC
- Last answered
- 2026-10-04 18:16 UTC
- Original
- open at the source
| 2026-10-03 00:06 UTC | Analyzed | | 2026-09-29 09:45 UTC | Awaiting Analysis |
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unknown",
"product": "Enterprise Server",
"vendor": "GitHub",
"versions": [
{
"changes": [
{
"at": "3.17.21",
"status": "unaffected"
}
],
"lessThan": "3.17.*",
"status": "affected",
"version": "3.17.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.18.15",
"status": "unaffected"
}
],
"lessThan": "3.18.*",
"status": "affected",
"version": "3.18.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.19.12",
"status": "unaffected"
}
],
"lessThan": "3.19.*",
"status": "affected",
"version": "3.19.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.20.8",
"status": "unaffected"
}
],
"lessThan": "3.20.*",
"status": "affected",
"version": "3.20.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.21.6",
"status": "unaffected"
}
],
"lessThan": "3.21.*",
"status": "affected",
"version": "3.21.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.22.1",
"status": "unaffected"
}
],
"lessThan": "3.22.*",
"status": "affected",
"version": "3.22.0",
"versionType": "semver"
}
]
}
],
"source": "product-cna@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E83141CB-1932-42B9-9425-48416C63A613",
"versionEndExcluding": "3.17.21",
"versionStartIncluding": "3.17.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "15CAF100-6E9B-4729-B9CB-9DC9A28476EE",
"versionEndExcluding": "3.18.15",
"versionStartIncluding": "3.18.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "1C9673F5-F19A-48A0-B9E9-C75E506A14E9",
"versionEndExcluding": "3.19.12",
"versionStartIncluding": "3.19.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "DCA88B70-765F-4318-82A3-67060A58BC31",
"versionEndExcluding": "3.20.8",
"versionStartIncluding": "3.20.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3E0F487F-1EC6-412C-BFC3-29FE2D88886E",
"versionEndExcluding": "3.21.6",
"versionStartIncluding": "3.21.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "78D23030-388E-448B-9C3D-3F89FA946F96",
"versionEndExcluding": "3.22.1",
"versionStartIncluding": "3.22.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the port, allowing requests to be directed to internal services listening on other ports of the same appliance. Response bodies were not returned to the requester, but response timing acted as an oracle that allowed instance secrets to be extracted character by character. An extracted secret could then be used in a separate interaction with an internal service to obtain remote code execution on the appliance. Exploitation required network access to the instance and was unauthenticated when private mode was disabled, or required any authenticated user when private mode was enabled. This vulnerability affected GitHub Enterprise Server versions 3.17 through 3.22 and was fixed in versions 3.22.1, 3.21.6, 3.20.8, 3.19.12, 3.18.15, and 3.17.21. This vulnerability was reported through the GitHub Bug Bounty program."
}
],
"id": "CVE-2026-77987",
"lastModified": "2026-10-02T18:37:45.130",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"cvssMetricV40": [
{
"cvssData": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"availabilityRequirement": "NOT_DEFINED",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"confidentialityRequirement": "NOT_DEFINED",
"exploitMaturity": "NOT_DEFINED",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"source": "product-cna@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-77987",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T15:26:50.899891Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-22T21:17:32.653",
"references": [
{
"source": "product-cna@github.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.21"
},
{
"source": "product-cna@github.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.15"
},
{
"source": "product-cna@github.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.12"
},
{
"source": "product-cna@github.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.8"
},
{
"source": "product-cna@github.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.6"
},
{
"source": "product-cna@github.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://docs.github.com/en/enterprise-server@3.22/admin/release-notes#3.22.1"
}
],
"sourceIdentifier": "product-cna@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-208"
},
{
"lang": "en",
"value": "CWE-918"
}
],
"source": "product-cna@github.com",
"type": "Secondary"
}
]
}
} |
|---|
| vendor | GitHubreceipt- Source
- NVD
- Its words
GitHub- Read by
field:cve.affected[].affectedData[].vendor- Said since
- 2026-09-29 17:49 UTC
- Last answered
- 2026-10-04 18:16 UTC
- Original
- open at the source
| 2026-09-29 17:49 UTC | GitHub | | 2026-09-29 09:45 UTC | — |
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unknown",
"product": "Enterprise Server",
"vendor": "GitHub",
"versions": [
{
"changes": [
{
"at": "3.17.21",
"status": "unaffected"
}
],
"lessThan": "3.17.*",
"status": "affected",
"version": "3.17.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.18.15",
"status": "unaffected"
}
],
"lessThan": "3.18.*",
"status": "affected",
"version": "3.18.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.19.12",
"status": "unaffected"
}
],
"lessThan": "3.19.*",
"status": "affected",
"version": "3.19.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.20.8",
"status": "unaffected"
}
],
"lessThan": "3.20.*",
"status": "affected",
"version": "3.20.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.21.6",
"status": "unaffected"
}
],
"lessThan": "3.21.*",
"status": "affected",
"version": "3.21.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "3.22.1",
"status": "unaffected"
}
],
"lessThan": "3.22.*",
"status": "affected",
"version": "3.22.0",
"versionType": "semver"
}
]
}
],
"source": "product-cna@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E83141CB-1932-42B9-9425-48416C63A613",
"versionEndExcluding": "3.17.21",
"versionStartIncluding": "3.17.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "15CAF100-6E9B-4729-B9CB-9DC9A28476EE",
"versionEndExcluding": "3.18.15",
"versionStartIncluding": "3.18.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "1C9673F5-F19A-48A0-B9E9-C75E506A14E9",
"versionEndExcluding": "3.19.12",
"versionStartIncluding": "3.19.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "DCA88B70-765F-4318-82A3-67060A58BC31",
"versionEndExcluding": "3.20.8",
"versionStartIncluding": "3.20.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3E0F487F-1EC6-412C-BFC3-29FE2D88886E",
"versionEndExcluding": "3.21.6",
"versionStartIncluding": "3.21.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "78D23030-388E-448B-9C3D-3F89FA946F96",
"versionEndExcluding": "3.22.1",
"versionStartIncluding": "3.22.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the port, allowing requests to be directed to internal services listening on other ports of the same appliance. Response bodies were not returned to the requester, but response timing acted as an oracle that allowed instance secrets to be extracted character by character. An extracted secret could then be used in a separate interaction with an internal service to obtain remote code execution on the appliance. Exploitation required network access to the instance and was unauthenticated when private mode was disabled, or required any authenticated user when private mode was enabled. This vulnerability affected GitHub Enterprise Server versions 3.17 through 3.22 and was fixed in versions 3.22.1, 3.21.6, 3.20.8, 3.19.12, 3.18.15, and 3.17.21. This vulnerability was reported through the GitHub Bug Bounty program."
}
],
"id": "CVE-2026-77987",
"lastModified": "2026-10-02T18:37:45.130",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"cvssMetricV40": [
{
"cvssData": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"availabilityRequirement": "NOT_DEFINED",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"confidentialityRequirement": "NOT_DEFINED",
"exploitMaturity": "NOT_DEFINED",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"source": "product-cna@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-77987",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T15:26:50.899891Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-22T21:17:32.653",
"references": [
{
"source": "product-cna@github.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.21"
},
{
"source": "product-cna@github.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.15"
},
{
"source": "product-cna@github.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.12"
},
{
"source": "product-cna@github.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.8"
},
{
"source": "product-cna@github.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.6"
},
{
"source": "product-cna@github.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://docs.github.com/en/enterprise-server@3.22/admin/release-notes#3.22.1"
}
],
"sourceIdentifier": "product-cna@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-208"
},
{
"lang": "en",
"value": "CWE-918"
}
],
"source": "product-cna@github.com",
"type": "Secondary"
}
]
}
} |
|---|