Executive brief
GitHub Enterprise Server is a self-hosted platform for software development and version control. A vulnerability was found where an authorized user could crash the server or make it unresponsive by uploading a specially crafted configuration file for repository release notes. This could lead to a total service outage for the organization until the system is recovered.
Technical details
A denial of service (DoS) vulnerability exists in GitHub Enterprise Server due to improper resource management during YAML parsing. The root cause is a lack of nesting depth limits when parsing repository release notes configuration files (CWE-770). An authenticated attacker can supply a configuration file containing deeply nested YAML structures; when the server attempts to generate release notes, it consumes excessive CPU and memory resources, potentially rendering the instance unresponsive. The issue affects all versions prior to 3.22 and has been patched in maintenance releases 3.17.18, 3.18.12, 3.19.9, 3.20.5, and 3.21.3.
Affected products
- GitHub Enterprise Server < 3.22; fixed in 3.17.18, 3.18.12, 3.19.9, 3.20.5, 3.21.3
Timeline
- 2026-07-17: advisory: NVD publication date
- 2026-07-17: disclosed: Vulnerability reported via GitHub Bug Bounty program
References
- https://docs.github.com/en/enterprise-server@3.17/admin/release-notes
- https://docs.github.com/en/enterprise-server@3.18/admin/release-notes
- https://docs.github.com/en/enterprise-server@3.19/admin/release-notes
- https://docs.github.com/en/enterprise-server@3.20/admin/release-notes
- https://docs.github.com/en/enterprise-server@3.21/admin/release-notes