Junglewise Threat Intelligence

CVE-2026-76851: GitHub Enterprise Server SSRF in pre-receive hooks leading to RCE

CVE-2026-76851 · Severity: high · CVSS 8.8 · Published 2026-09-01

Technologies: GitHub Enterprise Server. Vendors: GitHub.

Executive brief

GitHub Enterprise Server is a self-hosted platform for source code management and collaboration. A Server-Side Request Forgery vulnerability in pre-receive hook handling allowed attackers with administrative privileges or repository write access to execute arbitrary code on the instance by impersonating internal services. This could enable unauthorized access to sensitive data, system compromise, or lateral movement within an organization's infrastructure.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in GitHub Enterprise Server's pre-receive hook networking implementation due to insufficient network isolation. An attacker with either site administrator privileges or write access to a repository configured with pre-receive hooks could craft malicious hook code to impersonate an internal service and redirect trusted internal requests to a privileged service, leading to remote code execution with elevated privileges. Exploitation requires pre-receive hook networking to be explicitly enabled. The vulnerability affected all versions prior to 3.22 and was patched in 3.17.20, 3.18.14, 3.19.11, 3.20.7, and 3.21.5.

Affected products

  • GitHub Enterprise Server before 3.22 (fixed in 3.17.20, 3.18.14, 3.19.11, 3.20.7, 3.21.5)

Timeline

  • 2026-09-01: disclosed
  • 2026: patched: Patches released for versions 3.17.20, 3.18.14, 3.19.11, 3.20.7, 3.21.5

References