CVE-2026-19118
largeRace Condition RCE in GitHub Enterprise Server
CVE-2026-19118 is a time-of-check time-of-use (TOCTOU) race condition (CWE-367) in GitHub Enterprise Server that can lead to remote code execution. An attacker needs an authenticated account with write access to a repository and must time concurrent upload requests precisely to win the race window. If triggered successfully, the attacker gains remote code execution on the GHES appliance, taking control of the self-hosted instance and the code repositories it hosts. All versions of GitHub Enterprise Server prior to 3.22 are affected, and fixes are available in the 3.17.20, 3.18.14, 3.19.11, 3.20.7, and 3.21.5 maintenance releases. There is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.5% probability of exploitation within 30 days, so no exploitation is currently known.
What to do: Upgrade GitHub Enterprise Server to 3.17.20, 3.18.14, 3.19.11, 3.20.7, or 3.21.5 as soon as practicable; instances on 3.22 or later are not affected. Until patched, review which users hold repository write access (the required privilege for exploitation) and treat any accounts with broad write privileges as the exposure surface. No public exploit or in-the-wild exploitation is known, so standard patch-cycle prioritization is reasonable, but re-check the GHES version after applying maintenance updates.
| github enterprise server | All versions prior to 3.22; fixed in 3.17.20, 3.18.14, 3.19.11, 3.20.7, and 3.21.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution. Exploitation required an authenticated user with write access to a repository and precise timing of concurrent upload requests. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.17.20, 3.18.14, 3.19.11, 3.20.7, and 3.21.5. This vulnerability was reported via the GitHub Bug Bounty program.
- Vendors
- github
- Products
- enterprise server
- Weakness
- CWE-367
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.