PatchSiren cyber security CVE debrief
CVE-2026-96890 GitHub CVE debrief
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed requests to attacker-controlled internal hosts. The secret scanning validator for GCP service account credentials trusted the token endpoint embedded in a committed credential and issued a request to it without restricting the destination. Exploitation required an authenticated user with permission to push to a repository on an instance with GitHub Advanced Security and secret scanning validity checks enabled, a non-default configuration.
- Vendor
- GitHub
- Product
- Enterprise Server
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-06
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-06
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for GitHub Enterprise Server instances, especially those with GitHub Advanced Security and secret scanning enabled, should assess exposure and prioritize remediation.
Why it matters
The SSRF vulnerability in GitHub Enterprise Server allows attackers to issue requests to internal hosts, potentially leading to remote code execution. Defenders should prioritize verifying exposure, especially for instances with GitHub Advanced Security and secret scanning enabled, and ensure they are running fixed versions.
- Verify exposure of GitHub Enterprise Server instances
- Prioritize remediation for instances with GitHub Advanced Security and secret scanning enabled
- Monitor for suspicious activity on GitHub Enterprise Server instances
- Restrict secret scanning validator configurations
Technical summary
The SSRF vulnerability in GitHub Enterprise Server allowed requests to attacker-controlled internal hosts, which could be chained to achieve remote code execution on the appliance. The vulnerability affected GitHub Enterprise Server versions 3.20, 3.21, and 3.22 and was fixed in versions 3.20.9, 3.21.7, and 3.22.2. The secret scanning validator for GCP service account credentials trusted the token endpoint embedded in a committed credential and issued a request to it without restricting the destination. Defenders should prioritize verifying exposure of GitHub Enterprise Server instances, especially those with GitHub Advanced Security and secret scanning enabled, and ensure they are running fixed versions.
Defensive priority
Defenders should prioritize verifying exposure of GitHub Enterprise Server instances, especially those with GitHub Advanced Security and secret scanning enabled, and ensure they are running fixed versions 3.20.9, 3.21.7, or 3.22.2.
Recommended defensive actions
- Verify GitHub Enterprise Server instances for exposure, especially those with GitHub Advanced Security and secret scanning enabled
- Ensure instances are running fixed versions 3.20.9, 3.21.7, or 3.22.2
- Review and restrict secret scanning validator configurations
- Monitor for suspicious activity on GitHub Enterprise Server instances
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE record and source item provide details on the SSRF vulnerability in GitHub Enterprise Server, including affected versions (3.20, 3.21, and 3.22) and fixed versions (3.20.9, 3.21.7, and 3.22.2). Exploitation required an authenticated user with permission to push to a repository on an instance with GitHub Advanced Security and secret scanning validity checks enabled. Defenders should verify exposure, especially for instances with GitHub Advanced Security and secret scanning enabled, and ensure they are running fixed versions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-96890 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-96890
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-96890 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-96890
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowe
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/96xxx/CVE-2026-96890.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://docs.github.com/en/[email protected]/admin/release-notes
Supplemental source - release-notes
-
Source reference
Unverified legacy reference
URL: https://docs.github.com/en/[email protected]/admin/release-notes
Supplemental source - release-notes
-
Source reference
Unverified legacy reference
URL: https://docs.github.com/en/[email protected]/admin/release-notes
Supplemental source - release-notes
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.