GitHub security advisory (AV26-956)
Canadian Cyber Centre urges patches for vulnerabilities in GitHub Enterprise Server 3.17 through 3.22.
The Canadian Centre for Cyber Security issued advisory AV26-956 on September 23, 2026, stating that as of September 22 GitHub Enterprise Server is affected by vulnerabilities. Affected ranges are 3.17.0 before 3.17.21, 3.18.0 before 3.18.15, 3.19.0 before 3.19.12, 3.20.0 before 3.20.8, 3.21.0 before 3.21.6, and 3.22.0 before 3.22.1. The bulletin does not name CVEs or report exploitation and urges administrators to review GitHub release notes and apply updates.
- Canadian Cyber Centre advisory AV26-956, dated September 23, 2026.
- GitHub Enterprise Server 3.17 through 3.22 branches are affected.
- Fixed releases include 3.17.21, 3.18.15, 3.19.12, 3.20.8, 3.21.6, and 3.22.1.
- No CVE identifiers or active exploitation are stated.
Full article127 words · extracted from cyber.gc.ca · click to collapse
Serial Number: AV26-956
Date: September 23, 2026
As of September 22, 2026, GitHub is affected by vulnerabilities in the following product:
- Enterprise Server
- 3.17.0 Prior to 3.17.21
- 3.18.0 Prior to 3.18.15
- 3.19.0 Prior to 3.19.12
- 3.20.0 Prior to 3.20.8
- 3.21.0 Prior to 3.21.6
- 3.22.0 Prior to 3.22.1
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- Release notes - GitHub Enterprise Server 3.17 Docs
- Release notes - GitHub Enterprise Server 3.18 Docs
- Release notes - GitHub Enterprise Server 3.19 Docs
- Release notes - GitHub Enterprise Server 3.20 Docs
- Release notes - GitHub Enterprise Server 3.21 Docs
- Release notes - GitHub Enterprise Server 3.22 Docs
- GitHub Enterprise Server releases - GitHub Enterprise Server 3.19 Docs
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/github-security-advisory-av26-956