Executive brief
GitHub Enterprise Server contains a server-side request forgery (SSRF) vulnerability in its notebook viewer component that allows an attacker to send requests to internal services on the appliance. By exploiting timing side-channels, an attacker can extract instance secrets character-by-character, then use those secrets to gain remote code execution on the appliance. The vulnerability affects unpatched instances and requires network access, with minimal or no authentication required depending on the instance's private mode setting.
Technical details
The notebook viewer validates URL scheme and host but fails to validate the port parameter, allowing an attacker to redirect requests to internal services on alternate ports. Response timing acts as an oracle to extract secrets without returning response bodies. Exploitation chains this information disclosure to perform authenticated requests to internal services, achieving remote code execution. The vulnerability is unauthenticated on instances without private mode enabled, or requires any authenticated user when private mode is enabled.
Affected products
- GitHub Enterprise Server 3.17 through 3.22 (fixed in 3.17.21, 3.18.15, 3.19.12, 3.20.8, 3.21.6, 3.22.1)
Timeline
- 2026-09-22: disclosed
- 2026-09-22: patched: Patches released for versions 3.17.21, 3.18.15, 3.19.12, 3.20.8, 3.21.6, 3.22.1