CVE-2026-76851
largeSSRF to privileged RCE in GitHub Enterprise Server pre-receive hooks
CVE-2026-76851 is a server-side request forgery (SSRF) flaw in GitHub Enterprise Server in which insufficient network isolation lets malicious pre-receive hook code impersonate an internal service and redirect trusted internal requests to a privileged service. Exploitation requires pre-receive hook networking to be enabled on the instance, plus either site administrator privileges or write access to a repository that has a pre-receive hook configured. An attacker who meets those conditions gains remote code execution with elevated privileges on the GHES instance. All versions of GitHub Enterprise Server prior to 3.22 are affected, which applies to enterprise self-hosted or GitHub-managed instances rather than the github.com SaaS service. No public proof-of-concept or known in-the-wild exploitation exists; EPSS estimates the 30-day exploitation probability at about 0.5%.
What to do: Upgrade GitHub Enterprise Server to 3.17.20, 3.18.14, 3.19.11, 3.20.7, or 3.21.5 (or move to 3.22 or later). In the meantime, check whether pre-receive hook networking is enabled on your instance and audit which users hold site admin rights or write access to repositories with configured pre-receive hooks, restricting hook code to trusted authors. The issue was reported through GitHub's Bug Bounty program and is not currently listed in CISA's KEV.
| GitHub Enterprise Server | All versions prior to 3.22; fixed in 3.17.20, 3.18.14, 3.19.11, 3.20.7, and 3.21.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance. Insufficient network isolation allowed malicious pre-receive hook code to impersonate an internal service and redirect trusted internal requests to a privileged service, leading to elevated code execution. Exploitation required pre-receive hook networking to be enabled and either site administrator privileges or write access to a repository containing a configured pre-receive hook. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.17.20, 3.18.14, 3.19.11, 3.20.7, and 3.21.5. This vulnerability was reported via the GitHub Bug Bounty program.
- Vendors
- github
- Products
- enterprise server
- Weakness
- CWE-918
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.