PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-96890 GitHub CVE debrief

A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed requests to attacker-controlled internal hosts. The secret scanning validator for GCP service account credentials trusted the token endpoint embedded in a committed credential and issued a request to it without restricting the destination. Exploitation required an authenticated user with permission to push to a repository on an instance with GitHub Advanced Security and secret scanning validity checks enabled, a non-default configuration.

Vendor
GitHub
Product
Enterprise Server
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-06
Original CVE updated
2026-10-07
Advisory published
2026-10-06
Advisory updated
2026-10-07

Who should care

Defenders responsible for GitHub Enterprise Server instances, especially those with GitHub Advanced Security and secret scanning enabled, should assess exposure and prioritize remediation.

Why it matters

The SSRF vulnerability in GitHub Enterprise Server allows attackers to issue requests to internal hosts, potentially leading to remote code execution. Defenders should prioritize verifying exposure, especially for instances with GitHub Advanced Security and secret scanning enabled, and ensure they are running fixed versions.

  • Verify exposure of GitHub Enterprise Server instances
  • Prioritize remediation for instances with GitHub Advanced Security and secret scanning enabled
  • Monitor for suspicious activity on GitHub Enterprise Server instances
  • Restrict secret scanning validator configurations

Technical summary

The SSRF vulnerability in GitHub Enterprise Server allowed requests to attacker-controlled internal hosts, which could be chained to achieve remote code execution on the appliance. The vulnerability affected GitHub Enterprise Server versions 3.20, 3.21, and 3.22 and was fixed in versions 3.20.9, 3.21.7, and 3.22.2. The secret scanning validator for GCP service account credentials trusted the token endpoint embedded in a committed credential and issued a request to it without restricting the destination. Defenders should prioritize verifying exposure of GitHub Enterprise Server instances, especially those with GitHub Advanced Security and secret scanning enabled, and ensure they are running fixed versions.

Defensive priority

Defenders should prioritize verifying exposure of GitHub Enterprise Server instances, especially those with GitHub Advanced Security and secret scanning enabled, and ensure they are running fixed versions 3.20.9, 3.21.7, or 3.22.2.

Recommended defensive actions

  • Verify GitHub Enterprise Server instances for exposure, especially those with GitHub Advanced Security and secret scanning enabled
  • Ensure instances are running fixed versions 3.20.9, 3.21.7, or 3.22.2
  • Review and restrict secret scanning validator configurations
  • Monitor for suspicious activity on GitHub Enterprise Server instances
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The CVE record and source item provide details on the SSRF vulnerability in GitHub Enterprise Server, including affected versions (3.20, 3.21, and 3.22) and fixed versions (3.20.9, 3.21.7, and 3.22.2). Exploitation required an authenticated user with permission to push to a repository on an instance with GitHub Advanced Security and secret scanning validity checks enabled. Defenders should verify exposure, especially for instances with GitHub Advanced Security and secret scanning enabled, and ensure they are running fixed versions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-96890 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-96890

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-96890 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-96890

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.