GitHub security advisory (AV26-956)
Canadian Cyber Centre urges patches for vulnerabilities in GitHub Enterprise Server 3.17 through 3.22.
The Canadian Centre for Cyber Security issued advisory AV26-956 on September 23, 2026, stating that as of September 22 GitHub Enterprise Server is affected by vulnerabilities. Affected ranges are 3.17.0 before 3.17.21, 3.18.0 before 3.18.15, 3.19.0 before 3.19.12, 3.20.0 before 3.20.8, 3.21.0 before 3.21.6, and 3.22.0 before 3.22.1. The bulletin does not name CVEs or report exploitation and urges administrators to review GitHub release notes and apply updates.