OCTOBER 4, 2026
Live Feed
Back to database
Case File

CVE-2026-77987

CRITICAL · CVSS 9.8 EPSS 0.68% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-04

CyberRota Analysis

AI-Generated

A server-side request forgery (SSRF) vulnerability in the notebook viewer of GitHub Enterprise Server allows attackers to exploit the lack of port validation on user-supplied URLs, potentially leading to the extraction of instance secrets through timing attacks. This critical vulnerability can result in remote code execution if an attacker has network access to the instance, making it essential for organizations using affected versions (3.17 to 3.22) to prioritize immediate patching to mitigate the risk. All users of GitHub Enterprise Server should assess their exposure and update to the fixed versions promptly.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77987
Severity
CRITICAL
CVSS
9.8
EPSS
0.68%
Oracle GitHub

Original NVD Description

A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the port, allowing requests to be directed to internal services listening on other ports of the same appliance. Response bodies were not returned to the requester, but response timing acted as an oracle that allowed instance secrets to be extracted character by character. An extracted secret could then be used in a separate interaction with an internal service to obtain remote code execution on the appliance. Exploitation required network access to the instance and was unauthenticated when private mode was disabled, or required any authenticated user when private mode was enabled. This vulnerability affected GitHub Enterprise Server versions 3.17 through 3.22 and was fixed in versions 3.22.1, 3.21.6, 3.20.8, 3.19.12, 3.18.15, and 3.17.21. This vulnerability was reported through the GitHub Bug Bounty program.

Related CVEs

Other vulnerabilities affecting the same vendor(s)