GitHub security advisory (AV26-1007)
Canada's Cyber Centre urges admins to patch vulnerable GitHub Enterprise Server 3.18 through 3.22 releases.
The Canadian Centre for Cyber Security issued advisory AV26-1007 on October 7, 2026, warning that GitHub Enterprise Server is affected by vulnerabilities. Branches 3.18 through 3.22 are impacted below 3.18.16, 3.19.13, 3.20.9, 3.21.7, and 3.22.2 respectively. The notice does not name CVEs, give severity scores, or report exploitation, and it directs administrators to GitHub's release notes to apply updates.
- Advisory AV26-1007 covers GitHub Enterprise Server 3.18 through 3.22.
- Fixes are 3.18.16, 3.19.13, 3.20.9, 3.21.7, and 3.22.2.
- The bulletin lists no CVE IDs, scores, or exploitation evidence.
- Administrators are told to review GitHub release notes and update.
Full article109 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-1007
Date: October 7, 2026
As of October 6, 2026, GitHub is affected by vulnerabilities in the following product:
- Enterprise Server
- 3.18.0 Prior to 3.18.16
- 3.19.0 Prior to 3.19.13
- 3.20.0 Prior to 3.20.9
- 3.21.0 Prior to 3.21.7
- 3.22.0 Prior to 3.22.2
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/github-security-advisory-av26-1007